View Full Fortinet NSE6_SDW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 301
Which feature allows FortiGate to determine whether an SD-WAN path meets configured latency, jitter, or packet-loss requirements?
- Performance SLA
- DHCP
- DNS
- Static NAT
Correct Answer: 1
Explanation
Performance SLA is used to evaluate the quality and availability of SD-WAN paths against configured requirements. Depending on the health-check configuration, FortiGate can measure latency, jitter, packet loss, and reachability. These measurements help determine whether an SD-WAN member is suitable for traffic matching a particular rule. When a path no longer meets the required conditions, another eligible member can be selected according to the configured strategy. Performance SLA therefore provides the quality information needed for dynamic path selection. Proper thresholds are important because they should reflect the actual performance requirements of the applications using the WAN.
Question 302
Which SD-WAN strategy can distribute traffic across multiple eligible WAN members?
- Manual
- Best Quality
- Lowest Cost
- Load Balance
Correct Answer: 4
Explanation
Load Balance is designed to distribute traffic across multiple eligible SD-WAN members. This can help organizations make better use of several available WAN connections rather than leaving secondary links underutilized. Member eligibility can still depend on Performance SLA conditions and other SD-WAN rule requirements. The strategy is different from Best Quality, which focuses on measured path quality, and Manual, which uses an administrator-defined preference. Load balancing should be configured according to the organization’s bandwidth, application, and reliability requirements. It can be especially useful when several WAN paths provide acceptable performance and the organization wants to distribute traffic among them.
Question 303
Which metric represents the variation in packet delivery delay?
- Packet loss
- Latency
- Jitter
- Throughput
Correct Answer: 3
Explanation
Jitter represents variation in packet delivery delay. It is particularly important for real-time applications because packets need to arrive with relatively consistent timing. High jitter can cause interruptions or quality problems in voice and video traffic even when average latency appears acceptable. FortiGate can monitor jitter using Performance SLA health checks and compare the result with configured thresholds. Administrators can then use the SLA results to influence SD-WAN path selection. Jitter should be considered together with latency and packet loss because each metric describes a different aspect of WAN performance and reliability.
Question 304
Which Fortinet platform is designed to provide centralized configuration management for FortiGate devices?
- FortiAnalyzer
- FortiManager
- FortiMail
- FortiWeb
Correct Answer: 2
Explanation
FortiManager provides centralized management and configuration capabilities for FortiGate devices. In an SD-WAN environment with many branches, it can simplify administration by allowing common configurations to be managed centrally. Administrators can use FortiManager to maintain policies, device settings, routing-related configurations, and other network settings. This reduces the need to make identical changes manually on every FortiGate. FortiAnalyzer has a different primary purpose focused on log collection, analysis, and reporting. Together, FortiManager and FortiAnalyzer can provide centralized configuration management and operational visibility across a distributed Fortinet network.
Question 305
Which condition can cause an SD-WAN member to fail a Performance SLA?
- Excessive packet loss
- Having a configured hostname
- Using an Ethernet interface
- Having a valid IP address
Correct Answer: 1
Explanation
Excessive packet loss can cause an SD-WAN member to fail a Performance SLA when the measured value exceeds the configured threshold. Performance SLA can evaluate several characteristics of a WAN path, including packet loss, latency, jitter, and reachability. If a member fails the required conditions, it may become ineligible for traffic associated with the affected SD-WAN rule. Another eligible member can then be selected according to the configured strategy. Having a valid IP address or using a particular interface type does not automatically mean that the path provides acceptable application quality.
Question 306
Which Fortinet technology provides encrypted connectivity between FortiGate sites across an untrusted WAN?
- IPsec VPN
- DHCP
- DNS
- ARP
Correct Answer: 1
Explanation
IPsec VPN provides encrypted connectivity between FortiGate sites across WAN transports such as the public Internet. In an SD-WAN architecture, IPsec tunnels can form part of the secure overlay while the Internet or another WAN service provides the underlying transport. Multiple IPsec tunnels can provide additional path choices and redundancy. FortiGate can monitor these paths using Performance SLA and steer traffic using SD-WAN rules. This allows organizations to combine secure connectivity with dynamic path selection. Correct tunnel configuration, routing, authentication, and security settings are necessary for reliable operation.
Question 307
Which routing protocol can dynamically exchange network prefixes between FortiGate devices?
- DHCP
- DNS
- BGP
- NTP
Correct Answer: 3
Explanation
BGP can dynamically exchange network prefixes between FortiGate devices and other routing peers. It is useful in larger SD-WAN deployments because manually maintaining routes across many sites can become difficult. BGP can advertise and learn routes through suitable overlay connections, including IPsec-based designs. Routing policies can control which prefixes are advertised and how routes are preferred. SD-WAN and BGP provide complementary functions: BGP determines network reachability, while SD-WAN determines the forwarding path for matching traffic based on configured rules and path conditions. Careful route filtering is important for predictable operation.
Question 308
Which SD-WAN criterion can be used to match traffic destined for a recognized cloud service?
- Internet Service Database
- MAC address table
- DHCP scope
- ARP cache
Correct Answer: 1
Explanation
The Internet Service Database provides predefined information about supported Internet and cloud services. SD-WAN rules can use ISDB information to identify traffic destined for recognized services without manually entering every destination address. This is useful because large cloud platforms can use many IP addresses and may change their infrastructure over time. Administrators can create specific SD-WAN policies for recognized services and apply appropriate path-selection strategies. ISDB can therefore simplify traffic matching and reduce maintenance requirements. It is particularly useful when organizations need consistent WAN treatment for cloud applications and Internet-based services.
Question 309
Which SD-WAN strategy focuses primarily on selecting the member with suitable measured network quality?
- Manual
- Load Balance
- Best Quality
- Lowest Cost
Correct Answer: 3
Explanation
Best Quality focuses on selecting an SD-WAN member according to measured network quality. Performance SLA measurements can provide information about latency, jitter, packet loss, and reachability. FortiGate can use these results to determine which eligible path provides suitable quality for matching traffic. This strategy is useful for applications where performance is more important than selecting a path based primarily on cost or fixed preference. Administrators should configure appropriate health checks and thresholds so that the quality assessment accurately reflects application requirements. Best Quality can help traffic adapt when WAN performance changes over time.
Question 310
Which topology uses central devices as hubs for connecting multiple branch locations?
- Full Mesh
- Hub-and-Spoke
- Ring
- Point-to-Point
Correct Answer: 2
Explanation
A hub-and-spoke topology uses one or more central hub devices to connect multiple branch or spoke locations. This design can simplify centralized routing, security inspection, and management. However, branch-to-branch communication may need to pass through the hub, which can introduce additional latency and consume hub resources. Technologies such as ADVPN can provide dynamic shortcut connectivity between suitable spokes. SD-WAN can also be deployed across hub-and-spoke networks to select appropriate WAN paths based on application requirements and Performance SLA conditions. The topology is widely used when centralized control is an important design objective.
Question 311
Which SD-WAN strategy can explicitly use administrator-defined member preference?
- Best Quality
- Manual
- Load Balance
- Lowest Cost
Correct Answer: 2
Explanation
The Manual strategy allows administrators to define the preferred order of SD-WAN members. This is useful when a particular WAN link should normally be preferred while another link acts as a backup. The administrator has more direct control over the selection order than with quality-based strategies. Performance SLA conditions can still affect member eligibility depending on the configuration. Manual selection is useful when predictable path preference is required, although fixed preferences may not always reflect changing WAN conditions. Administrators should carefully consider reliability, cost, bandwidth, and application requirements when defining the member order.
Question 312
What does latency measure in an SD-WAN Performance SLA?
- Variation in packet timing
- Percentage of lost packets
- Delay experienced by traffic
- Available bandwidth
Correct Answer: 3
Explanation
Latency measures the delay experienced by traffic traveling across a monitored network path. High latency can negatively affect interactive applications such as voice, video conferencing, remote desktop, and transactional systems. FortiGate can measure latency through Performance SLA and compare the result against configured thresholds. If the measured latency exceeds the required value, the associated SD-WAN member may become unsuitable for a particular rule. Latency is different from jitter, which measures variation in delay, and packet loss, which measures unsuccessful packet delivery. Administrators should evaluate all relevant metrics when designing quality-based WAN policies.
Question 313
Which Fortinet solution is primarily responsible for centralized log analysis and reporting?
- FortiAnalyzer
- FortiManager
- FortiSwitch
- FortiClient
Correct Answer: 1
Explanation
FortiAnalyzer provides centralized log collection, analysis, reporting, and historical visibility. In an SD-WAN environment, FortiGate devices can send logs to FortiAnalyzer, allowing administrators to investigate network and security events across multiple locations. This centralized visibility can help with troubleshooting WAN problems, traffic behavior, and operational events. FortiManager is primarily focused on device and configuration management rather than log analysis. Using both platforms together can provide centralized configuration through FortiManager and centralized operational monitoring through FortiAnalyzer, which is valuable when managing many FortiGate devices across geographically distributed sites.
Question 314
Which technology can create dynamic shortcut paths between suitable branch locations in a hub-and-spoke environment?
- ADVPN
- DHCP
- DNS
- SNMP
Correct Answer: 1
Explanation
ADVPN can create dynamic shortcut connectivity between suitable branch locations in a hub-and-spoke environment. Without shortcuts, traffic between two spokes may need to pass through the central hub, creating additional latency and consuming hub resources. ADVPN can dynamically establish a more direct tunnel when the network configuration and routing conditions allow it. Fortinet deployments can combine ADVPN with IPsec and dynamic routing technologies to create scalable branch connectivity. SD-WAN can further control how traffic uses available paths. The exact behavior depends on the configured topology, routing, tunnel settings, and supported features.
Question 315
Which SD-WAN metric indicates that packets were not successfully delivered to the destination?
- Jitter
- Latency
- Packet loss
- Throughput
Correct Answer: 3
Explanation
Packet loss indicates that packets did not successfully reach their intended destination. High packet loss can cause retransmissions, application delays, and poor quality for real-time traffic. FortiGate can monitor packet loss through Performance SLA and compare the measurement against a configured threshold. If the threshold is exceeded, the affected SD-WAN member may become ineligible for traffic governed by that SLA. Packet loss differs from latency and jitter because it measures successful delivery rather than timing. Monitoring packet loss alongside latency and jitter provides a more complete assessment of WAN path quality.
Question 316
Which feature allows multiple SD-WAN members to be referenced through a logical grouping?
- SD-WAN zone
- DNS zone
- Security profile
- User group
Correct Answer: 1
Explanation
An SD-WAN zone provides a logical grouping of SD-WAN members. This can simplify configuration because policies or other settings can reference the logical zone rather than individually referencing multiple WAN members. The individual members still participate in path selection and can have their own health and performance characteristics. Logical grouping becomes especially useful in larger environments where several WAN connections need to be treated as a common service. Administrators should understand that the zone itself does not replace member-level path selection. SD-WAN strategies and Performance SLA conditions still determine which individual member is suitable.
Question 317
Which SD-WAN strategy considers member cost while also requiring acceptable SLA performance?
- Best Quality
- Load Balance
- Manual
- Lowest Cost (SLA)
Correct Answer: 4
Explanation
Lowest Cost (SLA) considers the cost of available SD-WAN members while also taking Performance SLA results into account. This allows administrators to prefer less expensive WAN services when they still meet the required quality conditions. If a lower-cost member fails the SLA, another eligible member can be selected. This approach helps balance WAN expenses with application performance requirements. Accurate cost values and realistic SLA thresholds are important because both influence path selection. The strategy is useful when an organization has several WAN transports with different costs and wants to use economical connectivity whenever it provides acceptable performance.
Question 318
Which component provides the physical transport on which an SD-WAN overlay can operate?
- Overlay
- Underlay
- Application Control
- Performance SLA
Correct Answer: 2
Explanation
The underlay provides the physical or transport connectivity on which the logical SD-WAN overlay operates. It can include Internet, MPLS, broadband, LTE, or other WAN services. The overlay can use IPsec tunnels or other logical mechanisms to provide secure connectivity between sites. SD-WAN evaluates the available paths and can steer traffic according to configured rules and Performance SLA measurements. Understanding the underlay is important during troubleshooting because an overlay problem can be caused by a degraded transport connection. Separating underlay and overlay also provides flexibility when adding or changing WAN services.
Question 319
Which SD-WAN rule criterion can be used to identify traffic coming from a particular internal subnet?
- Destination address
- Application
- Source address
- Internet Service Database
Correct Answer: 3
Explanation
The source address criterion can identify traffic originating from a particular internal subnet, host, or address group. This allows administrators to apply different SD-WAN behavior to different users, departments, or internal networks. For example, traffic from a business-critical subnet can be assigned stricter Performance SLA requirements than ordinary user traffic. Source matching can also be combined with destination, application, service, and ISDB criteria. This provides granular control over WAN path selection. Proper rule ordering and matching conditions are important because traffic must match the intended rule before the configured steering strategy can be applied.
Question 320
Which combination provides secure connectivity, application-aware steering, and WAN-quality-based path selection?
- DHCP, DNS, and ARP
- IPsec VPN, application-aware SD-WAN rules, and Performance SLA
- SMTP, FTP, and NTP
- SNMP, NAT, and MAC learning
Correct Answer: 2
Explanation
IPsec VPN, application-aware SD-WAN rules, and Performance SLA provide complementary functions in an SD-WAN deployment. IPsec can provide secure encrypted overlay connectivity between FortiGate sites. Application-aware SD-WAN rules identify relevant traffic and define how it should be steered across available paths. Performance SLA evaluates the current quality of those paths using measurements such as latency, jitter, packet loss, and reachability. If the preferred path becomes degraded, another eligible member can be selected according to the configured strategy. Together, these features provide secure connectivity and dynamic traffic steering based on both application requirements and current WAN conditions.