View Full Fortinet NSE6_SDW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 281
Which SD-WAN feature continuously evaluates the quality of configured WAN paths?
- Firewall policy
- Performance SLA
- DHCP server
- DNS database
Correct Answer: 2
Explanation
Performance SLA continuously evaluates configured WAN paths according to defined health-check parameters. Depending on the configuration, FortiGate can measure latency, jitter, packet loss, and reachability. The results help determine whether an SD-WAN member satisfies the conditions required by a particular rule. If a path becomes degraded, FortiGate can potentially select another eligible member according to the configured strategy. Performance SLA therefore provides the measurement and health information needed for quality-based SD-WAN decisions. Administrators should configure realistic thresholds so that normal variations do not cause unnecessary failover while genuine path degradation is detected quickly.
Question 282
Which SD-WAN strategy is intended to prefer a path based on current network quality?
- Manual
- Load Balance
- Best Quality
- Lowest Cost
Correct Answer: 3
Explanation
Best Quality is designed to prefer an SD-WAN member based on measured network quality. Performance SLA measurements can provide information such as latency, jitter, packet loss, and reachability. FortiGate uses these measurements when evaluating available members for traffic matching the relevant SD-WAN rule. This strategy is particularly useful for applications that depend on good network performance rather than simply using the cheapest or manually preferred connection. Administrators should define appropriate SLA thresholds and health-check targets so that the quality assessment accurately reflects the requirements of the applications being transported across the WAN.
Question 283
Which SD-WAN member attribute can be used to influence selection when path costs differ?
- Cost
- Hostname
- MAC address
- System uptime
Correct Answer: 1
Explanation
The cost associated with an SD-WAN member can influence path selection when a cost-aware strategy is used. This is particularly relevant when an organization has multiple WAN services with different operational or provider costs. For example, an administrator may want a lower-cost Internet connection to be preferred when it meets the required Performance SLA conditions, while an expensive MPLS circuit remains available for situations where quality requirements cannot be satisfied elsewhere. Cost values should reflect the intended business preference. They should be configured carefully because incorrect cost assignments can produce unexpected path-selection behavior.
Question 284
Which SD-WAN metric would directly indicate inconsistent delay between consecutive packets?
- Latency
- Packet loss
- Jitter
- Throughput
Correct Answer: 3
Explanation
Jitter represents variation in packet delay and therefore indicates inconsistent timing between packet deliveries. This metric is especially important for real-time applications such as voice and video conferencing. A path may have acceptable average latency while still suffering from high jitter, causing packets to arrive unevenly. FortiGate can monitor jitter through Performance SLA and use configured thresholds to determine path eligibility. Administrators should evaluate jitter together with latency and packet loss rather than treating any single metric as a complete representation of WAN quality. Appropriate SLA configuration helps identify paths that are unsuitable for sensitive applications.
Question 285
Which Fortinet solution provides centralized management for multiple FortiGate devices?
- FortiAnalyzer
- FortiManager
- FortiMail
- FortiClient
Correct Answer: 2
Explanation
FortiManager provides centralized management for multiple FortiGate devices. In a distributed SD-WAN deployment, this can simplify administration by allowing configurations, policies, and device information to be managed from a central platform. Administrators can use centralized configuration capabilities to maintain consistent settings across branch locations. FortiAnalyzer has a different primary role focused on centralized logging, analysis, and reporting. FortiManager is especially useful when the number of FortiGate devices grows because making identical changes individually on every branch can be time-consuming and can introduce configuration inconsistencies.
Question 286
Which technology is commonly used to create an encrypted SD-WAN overlay between FortiGate devices?
- IPsec VPN
- DHCP
- DNS
- ARP
Correct Answer: 1
Explanation
IPsec VPN is commonly used to create encrypted overlay connectivity between FortiGate devices. The underlying WAN transport can be an Internet circuit, MPLS connection, LTE service, or another transport. IPsec provides secure logical connectivity across that transport. Multiple tunnels can be used to create redundant paths, and SD-WAN can evaluate those paths for traffic forwarding. Performance SLA can monitor tunnel reachability and quality, while SD-WAN rules determine how matching traffic should use available members. This combination provides encrypted communication while allowing traffic to adapt to changing WAN conditions.
Question 287
Which routing protocol is commonly used for dynamic route exchange between SD-WAN sites?
- BGP
- FTP
- SMTP
- NTP
Correct Answer: 1
Explanation
BGP is commonly used for dynamic route exchange between FortiGate devices and other routing peers in SD-WAN environments. It can advertise and learn network prefixes dynamically, reducing the need for manually configured routes. BGP can operate across suitable overlay connections and can be combined with SD-WAN path selection. Routing policies can be applied to control advertisements and route preference. The exact design depends on the network topology and business requirements. Administrators should carefully configure route filtering and policy controls to prevent unintended route propagation and to maintain predictable routing behavior across the SD-WAN environment.
Question 288
What does packet loss indicate about a WAN path?
- Packets are experiencing variable delay
- Some packets are failing to reach their destination
- Packets are always arriving too quickly
- The path has unlimited bandwidth
Correct Answer: 2
Explanation
Packet loss indicates that some packets fail to successfully reach their destination. High packet loss can significantly affect network performance because applications may need to retransmit missing data or may experience degraded real-time communication. FortiGate can monitor packet loss through Performance SLA and compare it against configured thresholds. If a WAN member exceeds the acceptable limit, it may become ineligible for traffic governed by the associated SLA. Packet loss is different from latency and jitter. Monitoring all three metrics provides a more complete understanding of path quality and helps administrators make better SD-WAN steering decisions.
Question 289
Which SD-WAN feature can use predefined service information to match traffic destined for cloud applications?
- Internet Service Database
- ARP table
- DHCP scope
- MAC address table
Correct Answer: 1
Explanation
The Internet Service Database provides predefined information about supported Internet and cloud services. SD-WAN rules can use this information to match traffic without requiring administrators to manually maintain every destination IP address. This is useful for large cloud services that may use many addresses or frequently change their infrastructure. Administrators can create rules that apply different steering strategies to recognized services and combine them with Performance SLA requirements. Using ISDB can reduce policy maintenance and make application-specific traffic steering easier to manage across distributed SD-WAN environments.
Question 290
Which topology can use ADVPN to dynamically establish more direct communication between branch sites?
- Full Mesh only
- Hub-and-Spoke
- Ring only
- Broadcast
Correct Answer: 2
Explanation
ADVPN can provide dynamic shortcut connectivity in suitable hub-and-spoke deployments. In a traditional hub-and-spoke design, traffic between two spokes may travel through the central hub, which can create additional latency and consume hub resources. ADVPN can dynamically establish a more direct tunnel between spokes when the required conditions are met. This improves efficiency for inter-branch communication while maintaining a scalable centralized architecture. Fortinet deployments can combine ADVPN with IPsec, dynamic routing, and SD-WAN. The exact behavior depends on topology, tunnel configuration, routing, and supported FortiOS functionality.
Question 291
Which SD-WAN rule component identifies traffic based on the application generating it?
- Application
- Gateway address
- Physical speed
- Device serial number
Correct Answer: 1
Explanation
The Application criterion allows an SD-WAN rule to identify traffic according to the application generating or being used by that traffic. This enables administrators to provide different WAN treatment to different applications. For example, collaboration or business-critical applications can be assigned stricter Performance SLA requirements, while general browsing can use another strategy. Application matching can be combined with source, destination, service, and ISDB criteria. The FortiGate must be able to identify the application for the rule to match correctly. Application-aware steering provides more granular traffic control than relying only on destination addresses.
Question 292
Which Performance SLA metric measures the delay between sending and receiving traffic across a monitored path?
- Jitter
- Packet loss
- Latency
- Throughput
Correct Answer: 3
Explanation
Latency measures the delay experienced by traffic across a monitored network path. It is an important indicator for interactive applications because high delay can negatively affect responsiveness. FortiGate can measure latency through Performance SLA health checks and compare it with configured thresholds. If latency becomes excessive, the corresponding SD-WAN member may no longer satisfy the requirements of a rule. Latency should not be confused with jitter, which measures variation in delay, or packet loss, which measures unsuccessful packet delivery. Administrators should select thresholds based on the actual requirements of the applications using the WAN.
Question 293
Which Fortinet product is primarily designed to analyze and report on collected logs?
- FortiManager
- FortiAnalyzer
- FortiSwitch
- FortiClient
Correct Answer: 2
Explanation
FortiAnalyzer is primarily designed to collect, analyze, store, and report on logs from Fortinet devices. In an SD-WAN environment, it can provide centralized visibility into traffic behavior, connectivity events, and other operational information from multiple FortiGate systems. This is useful for troubleshooting and historical analysis. FortiManager focuses primarily on centralized management and configuration rather than log analysis. Using both products can provide a comprehensive management approach: FortiManager helps maintain consistent configurations, while FortiAnalyzer provides centralized visibility into events and network activity.
Question 294
Which strategy allows traffic to be spread across multiple suitable SD-WAN members?
- Manual
- Lowest Cost
- Best Quality
- Load Balance
Correct Answer: 4
Explanation
Load Balance allows traffic to be distributed across multiple eligible SD-WAN members. This can improve utilization of available WAN resources when multiple paths are suitable for the same traffic. Member eligibility can still be affected by Performance SLA requirements and other rule conditions. Load balancing differs from Best Quality, which focuses on measured network performance, and Manual, which follows administrator-defined preference. Organizations should consider link bandwidth, application sensitivity, provider costs, and failure behavior when selecting a strategy. Proper configuration can help prevent unnecessary congestion on a single WAN connection while making better use of available capacity.
Question 295
What is the primary purpose of an SD-WAN zone?
- To logically group SD-WAN members
- To store FortiAnalyzer reports
- To create administrator accounts
- To provide DNS resolution
Correct Answer: 1
Explanation
An SD-WAN zone can logically group SD-WAN members so that configurations can reference the group as a logical WAN service. This simplifies policy and routing configuration when several members should be treated as part of the same logical interface or service. Individual members remain available for SD-WAN path selection, health monitoring, and other functions. Logical grouping is particularly useful in larger deployments where multiple WAN links need to be managed consistently. Administrators should understand the distinction between the logical zone and the individual members because SD-WAN strategies still operate on the available paths.
Question 296
Which SD-WAN strategy is designed to select a lower-cost member when it meets the required SLA conditions?
- Best Quality
- Lowest Cost (SLA)
- Load Balance
- Manual
Correct Answer: 2
Explanation
Lowest Cost (SLA) is designed to consider WAN member cost while also requiring acceptable Performance SLA conditions. This allows an organization to prefer a less expensive WAN service when it still meets the quality requirements for the traffic. If the lower-cost member fails the SLA, another eligible member can be selected. This strategy can help balance WAN operating expenses and application performance. Administrators should configure meaningful cost values and realistic SLA thresholds because both factors influence the final selection. It is especially useful when multiple WAN transports have different costs and reliability characteristics.
Question 297
Which SD-WAN architecture uses physical WAN services as transport for logical overlay connections?
- Underlay/Overlay architecture
- DNS/DHCP architecture
- User/Group architecture
- Policy/Profile architecture
Correct Answer: 1
Explanation
Underlay/Overlay architecture separates the physical WAN transports from the logical connectivity built across them. The underlay can include Internet, MPLS, broadband, or cellular connections. The overlay can use IPsec tunnels to provide secure logical communication between network sites. SD-WAN can then evaluate these available paths and steer traffic according to configured rules and Performance SLA results. This architecture gives organizations flexibility to use different transport providers while maintaining a consistent logical network design. It also helps administrators troubleshoot problems by identifying whether an issue originates in the transport underlay or the logical overlay.
Question 298
Which condition can cause an SD-WAN member to be excluded from a rule’s eligible paths?
- Failure to meet the configured Performance SLA
- Having a valid IP address
- Being connected to a WAN interface
- Having a configured description
Correct Answer: 1
Explanation
Failure to meet the configured Performance SLA can cause an SD-WAN member to become ineligible for traffic governed by that SLA. For example, excessive latency, jitter, packet loss, or loss of reachability may cause the member to fail the required health-check conditions. FortiGate can then evaluate other members and select an eligible path according to the configured strategy. This provides dynamic response to WAN degradation. Simply having an active interface does not guarantee that the path is suitable for every application. Performance-based eligibility allows SD-WAN to make forwarding decisions based on actual network conditions.
Question 299
Which feature can help an administrator centrally deploy consistent SD-WAN settings to many FortiGate branches?
- FortiManager Configuration Templates
- FortiAnalyzer Reports
- DHCP Relay
- DNS Forwarding
Correct Answer: 1
Explanation
FortiManager Configuration Templates can help administrators deploy consistent SD-WAN-related configurations across multiple FortiGate branches. This is useful when many sites share common requirements for interfaces, VPNs, routing, security policies, and SD-WAN rules. Centralized templates reduce repetitive manual work and improve consistency. Administrators can maintain a common baseline while accommodating device-specific values where necessary. This becomes increasingly valuable as an SD-WAN environment grows. Instead of making the same configuration change independently on many devices, administrators can manage the configuration centrally and apply it systematically to appropriate FortiGate devices.
Question 300
Which combination is most appropriate for dynamically steering critical application traffic according to WAN quality?
- Static ARP and DHCP
- Application-aware SD-WAN rules and Performance SLA
- DNS and NTP
- SMTP and FTP
Correct Answer: 2
Explanation
Application-aware SD-WAN rules combined with Performance SLA provide a mechanism for steering critical application traffic according to current WAN conditions. The SD-WAN rule identifies the relevant application and specifies the desired path-selection behavior. Performance SLA evaluates available members using measurements such as latency, jitter, packet loss, and reachability. If the preferred path becomes degraded, another eligible member can be selected according to the configured strategy. This approach allows administrators to align WAN behavior with application requirements while adapting to changing network conditions. It is more flexible than relying solely on static routing or physical interface status.