Fortinet NSE6_SDW_AD-7.6 Practice Test Questions and Exam Dumps Part17 Q321-340

View Full Fortinet NSE6_SDW_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 321

Which SD-WAN mechanism determines whether a WAN member satisfies configured network-quality requirements?

  1. Performance SLA
  2. DHCP
  3. DNS
  4. Static NAT

Correct Answer: 1

Explanation

Performance SLA evaluates WAN member quality against configured health-check requirements. Depending on the configuration, FortiGate can measure latency, jitter, packet loss, and reachability. These measurements allow SD-WAN to determine whether a particular member is suitable for traffic matching a rule. If a member fails the required SLA conditions, another eligible path can be selected according to the configured strategy. This makes Performance SLA an important part of dynamic SD-WAN path selection. Administrators should select realistic thresholds based on application requirements because thresholds that are too strict or too relaxed can result in undesirable path-selection behavior.

Question 322

Which SD-WAN strategy is designed to select paths according to measured network quality?

  1. Manual
  2. Load Balance
  3. Best Quality
  4. Lowest Cost

Correct Answer: 3

Explanation

Best Quality uses measured network performance when selecting an appropriate SD-WAN member. Performance SLA can provide measurements such as latency, jitter, packet loss, and reachability. FortiGate can use those measurements when evaluating the available members for matching traffic. This strategy is particularly useful for applications that require good network quality, such as voice, video, or critical business applications. Unlike Manual selection, it does not rely solely on a fixed administrator-defined preference. Proper health-check targets and SLA thresholds are important so that FortiGate can accurately identify paths that meet the required performance level.

Question 323

Which SD-WAN metric measures the percentage of packets that fail to reach their destination?

  1. Latency
  2. Jitter
  3. Packet loss
  4. Throughput

Correct Answer: 3

Explanation

Packet loss measures packets that fail to successfully reach their destination. High packet loss can negatively affect many types of applications because data may need to be retransmitted, while real-time applications can experience interruptions or degraded quality. FortiGate can monitor packet loss using Performance SLA and compare the measured value against configured thresholds. When a member exceeds the acceptable limit, it may become ineligible for traffic associated with the relevant SD-WAN rule. Packet loss differs from latency, which measures delay, and jitter, which measures variation in delay.

Question 324

Which Fortinet product is primarily used for centralized configuration and device management?

  1. FortiAnalyzer
  2. FortiManager
  3. FortiMail
  4. FortiWeb

Correct Answer: 2

Explanation

FortiManager provides centralized configuration and device management for FortiGate deployments. In an SD-WAN environment, it allows administrators to manage multiple branch devices from a centralized platform. Common configurations, policies, routing settings, and SD-WAN-related settings can be maintained more efficiently. This reduces repetitive administrative work and helps improve configuration consistency. FortiAnalyzer has a different primary role, focusing on centralized log collection, analysis, and reporting. Organizations can use both products together, with FortiManager providing centralized management and FortiAnalyzer providing centralized operational visibility.

Question 325

Which SD-WAN strategy can distribute traffic among multiple eligible members?

  1. Load Balance
  2. Manual
  3. Best Quality
  4. Lowest Cost

Correct Answer: 1

Explanation

Load Balance distributes traffic across multiple eligible SD-WAN members. This can help utilize available WAN bandwidth more efficiently when several paths satisfy the requirements of the relevant traffic. Performance SLA conditions can still determine whether a member is eligible. Load Balance differs from Best Quality, which focuses on network performance, and Manual, which uses an administrator-defined order. Administrators should consider the capacity and characteristics of each WAN link when using load balancing. Proper configuration can prevent overuse of one connection while making better use of multiple available transport paths.

Question 326

Which technology can provide encrypted overlay connectivity between FortiGate sites?

  1. DHCP
  2. IPsec VPN
  3. DNS
  4. ARP

Correct Answer: 2

Explanation

IPsec VPN provides encrypted logical connectivity between FortiGate sites and is commonly used as an SD-WAN overlay. The underlying transport can be Internet, MPLS, LTE, or another WAN service. IPsec protects traffic while the SD-WAN system can evaluate and steer traffic across available paths. Multiple tunnels can provide redundancy and additional path choices. Performance SLA can monitor the quality and reachability of those paths. This combination allows organizations to use different WAN transports while maintaining secure connectivity between branches, data centers, and other locations.

Question 327

Which protocol can dynamically advertise and learn network prefixes between SD-WAN sites?

  1. SMTP
  2. DHCP
  3. BGP
  4. DNS

Correct Answer: 3

Explanation

BGP can dynamically advertise and learn network prefixes between FortiGate devices and other routing peers. It is useful in larger SD-WAN environments where manually maintaining routes across many sites becomes difficult. BGP can operate across suitable overlay connections and can exchange routing information between hubs and branches. Administrators can apply routing policies to control route advertisements and route preference. BGP and SD-WAN perform complementary functions: BGP provides dynamic reachability information, while SD-WAN can determine how matching traffic should use available paths according to policy and path quality.

Question 328

Which metric is especially important for real-time traffic because it measures variation in packet timing?

  1. Jitter
  2. Packet loss
  3. Latency
  4. Throughput

Correct Answer: 1

Explanation

Jitter measures variation in packet delivery timing and is particularly important for real-time applications such as voice and video. High jitter can cause packets to arrive unevenly, resulting in interruptions, distortion, or reduced quality. FortiGate can monitor jitter through Performance SLA health checks and compare the results against configured thresholds. A path may have acceptable average latency while still having excessive jitter. Therefore, administrators should consider multiple metrics when evaluating WAN quality. Configuring suitable jitter thresholds can help ensure that real-time applications are steered toward paths that provide more consistent packet delivery.

Question 329

Which Fortinet solution is primarily responsible for centralized log analysis and reporting?

  1. FortiManager
  2. FortiGate
  3. FortiAnalyzer
  4. FortiSwitch

Correct Answer: 3

Explanation

FortiAnalyzer provides centralized log collection, analysis, reporting, and monitoring. FortiGate devices can send logs to FortiAnalyzer, allowing administrators to review events from multiple sites through a centralized platform. In an SD-WAN environment, this can help identify connectivity problems, traffic patterns, security events, and operational changes. FortiManager focuses on centralized device and configuration management rather than log analysis. Using both platforms together can provide a comprehensive management approach for distributed environments. FortiManager can manage configurations while FortiAnalyzer provides historical and centralized visibility into network events.

Question 330

Which SD-WAN topology commonly uses a central location to connect multiple branches?

  1. Full Mesh
  2. Hub-and-Spoke
  3. Ring
  4. Point-to-Point

Correct Answer: 2

Explanation

Hub-and-Spoke uses one or more central hub locations to connect multiple branch or spoke sites. This topology simplifies centralized routing, security inspection, and management. However, branch-to-branch traffic may need to travel through the hub, potentially creating additional latency and consuming hub resources. Fortinet ADVPN can provide dynamic shortcuts between suitable spokes when configured appropriately. SD-WAN can operate within this architecture to select paths based on application requirements and WAN conditions. Hub-and-spoke is commonly used when centralized control and scalable branch connectivity are important design objectives.

Question 331

Which SD-WAN strategy allows an administrator to specify the preferred member order manually?

  1. Lowest Cost
  2. Best Quality
  3. Manual
  4. Load Balance

Correct Answer: 3

Explanation

The Manual strategy allows administrators to define the preferred order of SD-WAN members. This can be useful when a particular WAN link should normally carry traffic and another link should be used as a backup. Manual preference provides predictable selection based on administrator configuration rather than primarily ranking members according to measured quality. Performance SLA can still influence member eligibility when configured. Administrators should carefully consider link reliability and application requirements because a fixed preference may not always represent the best path when network conditions change. Manual strategy is therefore useful when explicit path preference is required.

Question 332

Which SD-WAN rule criterion can match traffic based on where it is going?

  1. Source address
  2. Destination address
  3. Administrator account
  4. Device serial number

Correct Answer: 2

Explanation

Destination address allows an SD-WAN rule to identify traffic based on its intended destination. This can be useful when different destinations need different WAN treatment. For example, traffic to a corporate data center can be assigned a specific path preference while general Internet traffic follows another rule. Destination matching can be combined with source, application, service, or ISDB criteria for more granular control. Once traffic matches the appropriate rule, FortiGate applies the configured strategy and evaluates eligible members according to the relevant Performance SLA conditions.

Question 333

What does a high latency value indicate about a WAN path?

  1. Significant packet delay
  2. Guaranteed high bandwidth
  3. Zero packet loss
  4. Perfect application performance

Correct Answer: 1

Explanation

A high latency value indicates significant packet delay across the monitored WAN path. High delay can negatively affect interactive applications because users may experience slow responses and delayed communication. Applications such as voice, video conferencing, remote desktop, and transactional systems can be particularly sensitive to excessive latency. Performance SLA can monitor latency and compare it with configured thresholds. If the path fails the required threshold, it may become unsuitable for an SD-WAN rule. Latency should be evaluated alongside jitter and packet loss because a path with low delay can still experience other quality problems.

Question 334

Which feature can identify predefined Internet services for SD-WAN traffic matching?

  1. Internet Service Database
  2. ARP
  3. DHCP
  4. NTP

Correct Answer: 1

Explanation

The Internet Service Database provides predefined information about supported Internet services and their destinations. SD-WAN rules can use ISDB information to identify traffic without requiring administrators to manually maintain every destination IP address. This is useful for cloud applications and other Internet services that may use large or changing address ranges. Administrators can create service-specific steering policies and combine them with Performance SLA requirements. Using ISDB can simplify configuration and reduce ongoing maintenance. It is especially valuable when an organization wants consistent SD-WAN behavior for recognized cloud applications and Internet-based services.

Question 335

Which event can cause an SD-WAN member to become ineligible for a rule using Performance SLA?

  1. Exceeding the configured latency threshold
  2. Having a configured IP address
  3. Using a physical interface
  4. Having a valid gateway

Correct Answer: 1

Explanation

Exceeding the configured latency threshold can cause an SD-WAN member to fail the associated Performance SLA. If the measured latency becomes higher than the configured acceptable value, FortiGate may consider the member unsuitable for traffic governed by that SLA. Other metrics such as jitter, packet loss, and reachability can also affect eligibility depending on the health-check configuration. When another member meets the requirements, the configured SD-WAN strategy can select that path. This provides dynamic response to degraded WAN conditions without requiring administrators to manually modify routes whenever network performance changes.

Question 336

Which technology can reduce branch-to-branch traffic hairpinning through a central hub?

  1. ADVPN
  2. DHCP
  3. DNS
  4. SNMP

Correct Answer: 1

Explanation

ADVPN can reduce branch-to-branch traffic hairpinning by enabling dynamic shortcut connectivity between suitable spoke locations. In a traditional hub-and-spoke design, traffic between two branches may travel through the central hub even when a direct path would be more efficient. ADVPN can dynamically establish a shortcut when the required configuration and routing conditions are satisfied. This can reduce latency and improve resource utilization at the hub. Fortinet deployments can combine ADVPN with IPsec, dynamic routing, and SD-WAN technologies to provide scalable and efficient branch connectivity.

Question 337

Which SD-WAN strategy focuses on minimizing path cost while still considering SLA requirements?

  1. Load Balance
  2. Best Quality
  3. Lowest Cost (SLA)
  4. Manual

Correct Answer: 3

Explanation

Lowest Cost (SLA) considers the cost of WAN members while also requiring acceptable Performance SLA results. This allows organizations to prefer lower-cost WAN services when those services provide sufficient quality for the traffic. If the lower-cost member fails the required SLA conditions, another eligible member can be selected. This strategy can help balance WAN expenses with application performance. Administrators should configure realistic cost values and SLA thresholds because both influence path selection. It is particularly useful when multiple WAN providers offer different pricing and performance characteristics.

Question 338

Which FortiManager feature helps administrators deploy a common configuration across multiple FortiGate branches?

  1. Configuration Templates
  2. Packet Capture
  3. Traffic Shaping
  4. DNS Filtering

Correct Answer: 1

Explanation

Configuration Templates in FortiManager allow administrators to create standardized configurations that can be applied to multiple FortiGate devices. This is useful in SD-WAN deployments where branches often share common settings for interfaces, VPNs, routing, firewall policies, and SD-WAN rules. Templates reduce repetitive manual configuration and improve consistency across the environment. Device-specific parameters can still be customized where required. Centralized template management becomes increasingly valuable as the number of branches grows because administrators can maintain a common baseline and apply changes systematically rather than modifying each device independently.

Question 339

Which metric should be monitored when an administrator is concerned about packets arriving at inconsistent intervals?

  1. Packet loss
  2. Jitter
  3. Latency
  4. Throughput

Correct Answer: 2

Explanation

Jitter should be monitored when packet arrival timing is inconsistent. It measures variation in packet delay and is particularly important for applications that require continuous and predictable packet delivery. Voice and video applications can be negatively affected by high jitter even when average latency is acceptable. FortiGate can use Performance SLA to monitor jitter and compare it against configured thresholds. If a path fails the required conditions, an alternative SD-WAN member may be selected. Monitoring jitter together with latency and packet loss provides a more complete understanding of whether a WAN path is appropriate for sensitive traffic.

Question 340

Which combination enables FortiGate to identify important applications and select suitable WAN paths based on current network conditions?

  1. DHCP and DNS
  2. Application-aware SD-WAN rules and Performance SLA
  3. ARP and NAT
  4. NTP and SMTP

Correct Answer: 2

Explanation

Application-aware SD-WAN rules and Performance SLA work together to provide intelligent traffic steering. The application-aware rule identifies traffic according to its application and defines how that traffic should be handled. Performance SLA evaluates the current quality of available WAN members using measurements such as latency, jitter, packet loss, and reachability. If the preferred member becomes degraded, another eligible member can be selected according to the configured strategy. This approach allows administrators to give important applications specific WAN treatment while adapting to changing network conditions. It provides more flexible control than relying only on static routes or interface availability.