Fortinet NSE6_SDW_AD-7.6 Practice Test Questions and Exam Dumps Part18 Q341-360

View Full Fortinet NSE6_SDW_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 341

Which component determines whether an SD-WAN path meets configured latency, jitter, and packet-loss requirements?

  1. Firewall policy
  2. Performance SLA
  3. DNS database
  4. DHCP server

Correct Answer: 2

Explanation

Performance SLA is responsible for measuring WAN path quality against configured requirements. It can evaluate metrics such as latency, jitter, packet loss, and reachability depending on the health-check configuration. FortiGate uses these measurements to determine whether SD-WAN members are suitable for traffic matching a particular rule. If a member fails the required SLA conditions, another eligible path can be selected according to the configured SD-WAN strategy. This dynamic evaluation allows traffic steering to respond to changing WAN conditions. Proper SLA thresholds are important because unrealistic values can cause unnecessary path changes or fail to detect genuine degradation.

Question 342

An administrator wants business-critical traffic to prefer the WAN path with the best measured quality. Which SD-WAN strategy is most appropriate?

  1. Manual
  2. Load Balance
  3. Lowest Cost
  4. Best Quality

Correct Answer: 4

Explanation

Best Quality is designed to select an appropriate SD-WAN member based on measured network quality. Performance SLA measurements can include latency, jitter, packet loss, and other health indicators. This makes the strategy useful for applications where network performance is more important than simply selecting a fixed or low-cost link. For example, voice or video traffic may benefit from a path with lower latency and jitter. If the preferred path deteriorates and no longer satisfies the relevant conditions, FortiGate can use another eligible member. Administrators should configure health checks and thresholds carefully to make quality-based selection effective.

Question 343

Which SD-WAN rule criterion can be used to steer traffic originating from a specific internal subnet?

  1. Source address
  2. Destination address
  3. Internet Service Database
  4. Application category

Correct Answer: 1

Explanation

Source address allows an SD-WAN rule to identify traffic based on where it originates. An administrator can use this criterion to apply different WAN path-selection behavior to different internal networks, users, or server segments. For example, traffic from a voice VLAN could be given different path requirements from traffic generated by a guest network. Source-based matching can also be combined with destination, application, service, or ISDB criteria. After traffic matches the rule, the configured SD-WAN strategy and Performance SLA conditions determine which eligible WAN member should be used.

Question 344

What is a major advantage of using multiple WAN members in an SD-WAN deployment?

  1. It removes the need for routing
  2. It guarantees zero packet loss
  3. It provides path redundancy and traffic-steering options
  4. It eliminates firewall policies

Correct Answer: 3

Explanation

Multiple WAN members provide redundancy and additional path choices for traffic steering. If one connection becomes unavailable or fails the required Performance SLA conditions, FortiGate can potentially use another eligible member. Multiple links can also be used for load distribution or application-specific steering. This improves flexibility compared with relying on a single WAN connection. However, multiple WAN links do not automatically guarantee perfect connectivity or zero packet loss. Their effectiveness depends on correct SD-WAN rules, routing, health checks, security policies, and appropriate SLA thresholds. Administrators should design the configuration around application requirements and the characteristics of each WAN service.

Question 345

Which protocol is commonly used to create an encrypted tunnel between two FortiGate devices?

  1. IPsec
  2. FTP
  3. SMTP
  4. SNMP

Correct Answer: 1

Explanation

IPsec is commonly used to create encrypted VPN tunnels between FortiGate devices. In SD-WAN deployments, IPsec tunnels can serve as secure overlay paths across different WAN underlays such as broadband, MPLS, or LTE. Multiple IPsec tunnels can provide additional path choices and redundancy. SD-WAN can then evaluate those paths using configured rules and Performance SLA measurements. IPsec protects the traffic while SD-WAN determines how traffic should be steered. This separation between secure overlay connectivity and path-selection logic allows organizations to build flexible WAN architectures while maintaining encrypted communication between sites.

Question 346

Which routing protocol is particularly useful when many SD-WAN sites need dynamic exchange of network prefixes?

  1. OSPF
  2. BGP
  3. ARP
  4. DHCP

Correct Answer: 2

Explanation

BGP can dynamically exchange network prefixes between FortiGate devices and other routing peers. In larger SD-WAN environments, dynamic routing reduces the need to manually configure numerous routes on every branch. BGP can advertise branch networks through suitable overlay or underlay connections, depending on the design. SD-WAN then provides traffic-steering capabilities independently of the routing protocol. Administrators can use routing policies to control which prefixes are advertised or preferred. BGP is especially useful in scalable environments where the number of branches, hubs, or dynamically changing network paths makes static route management difficult.

Question 347

Which condition most directly indicates that packets are arriving with inconsistent delays?

  1. High throughput
  2. Low latency
  3. High jitter
  4. Low packet loss

Correct Answer: 3

Explanation

High jitter indicates significant variation in packet arrival timing. This is particularly important for real-time applications such as VoIP, video conferencing, and interactive media. Even when average latency is relatively low, inconsistent packet timing can cause audio or video quality problems. FortiGate Performance SLA can measure jitter when the configured health-check mechanism supports it. Administrators can define an acceptable threshold and use that information in SD-WAN path selection. A path with excessive jitter may become unsuitable for sensitive traffic even if its bandwidth and average latency appear acceptable.

Question 348

Which Fortinet platform is designed to provide centralized log analysis and reporting for FortiGate devices?

  1. FortiAnalyzer
  2. FortiManager
  3. FortiAuthenticator
  4. FortiMail

Correct Answer: 1

Explanation

FortiAnalyzer is designed for centralized log collection, analysis, reporting, and monitoring. In an SD-WAN environment, multiple FortiGate devices can send logs to FortiAnalyzer, giving administrators a centralized view of events across branches and WAN connections. This can help with troubleshooting, security analysis, and operational reporting. FortiManager serves a different primary purpose: centralized device and configuration management. Using FortiManager and FortiAnalyzer together can provide both configuration control and centralized visibility. FortiAnalyzer can therefore be useful when administrators need to investigate historical events or analyze activity across a distributed SD-WAN deployment.

Question 349

Which SD-WAN strategy can use multiple eligible links to distribute traffic rather than relying on only one preferred path?

  1. Manual
  2. Best Quality
  3. Load Balance
  4. Lowest Cost

Correct Answer: 3

Explanation

Load Balance is intended to distribute traffic across eligible SD-WAN members. Instead of concentrating all matching traffic on one preferred connection, FortiGate can use multiple available members according to the configured load-balancing behavior. This can improve utilization of available WAN capacity and reduce dependence on a single connection. Performance SLA can still determine whether members are eligible when SLA requirements are configured. Administrators should consider the bandwidth, latency, cost, and reliability of each WAN service before using load balancing. Different applications may also require separate SD-WAN rules if they have specific performance or path requirements.

Question 350

In a traditional hub-and-spoke topology, where is branch-to-branch traffic commonly forwarded if no direct shortcut exists?

  1. Through the central hub
  2. Directly between all branches
  3. Through the DNS server
  4. Through the FortiAnalyzer

Correct Answer: 1

Explanation

In a traditional hub-and-spoke topology, branch sites generally connect through a central hub. Therefore, traffic traveling from one spoke to another may be forwarded through the hub when a direct spoke-to-spoke path is not available. This architecture can simplify centralized security inspection and routing but may increase latency and consume hub resources for inter-branch communication. Technologies such as ADVPN can provide dynamic shortcuts between suitable spokes, reducing the need for traffic to hairpin through the hub. SD-WAN can then help select appropriate paths based on configured rules and network-quality measurements.

Question 351

Which SD-WAN strategy allows an administrator to define a fixed preference order for WAN members?

  1. Best Quality
  2. Manual
  3. Load Balance
  4. Lowest Cost

Correct Answer: 2

Explanation

The Manual strategy allows administrators to define a specific preference order for SD-WAN members. This is useful when an organization wants one WAN connection to be preferred under normal circumstances and another connection to act as a backup. The configuration provides predictable path preference rather than dynamically selecting based primarily on quality or cost. Performance SLA can still be relevant for determining whether a member is eligible, depending on the rule configuration. Manual selection is useful for environments where administrators have clear operational requirements for which links should be used first.

Question 352

Which measurement represents the time required for traffic to travel between a source and a destination?

  1. Packet loss
  2. Jitter
  3. Latency
  4. Throughput

Correct Answer: 3

Explanation

Latency represents the delay experienced by traffic between a source and destination. Lower latency is generally preferable for interactive applications because responses can be delivered more quickly. High latency can affect applications such as remote desktops, voice communications, database transactions, and other interactive services. FortiGate can monitor latency through Performance SLA health checks and compare the measured value against configured thresholds. If latency becomes unacceptable, the corresponding WAN member may fail the SLA requirements for a particular SD-WAN rule. Latency should be evaluated together with packet loss and jitter to obtain a more complete view of WAN performance.

Question 353

Which FortiManager capability is useful for maintaining consistent SD-WAN configurations across many FortiGate devices?

  1. Configuration Templates
  2. Packet Capture
  3. DNS Filtering
  4. Antivirus Scanning

Correct Answer: 1

Explanation

Configuration Templates in FortiManager help administrators maintain standardized configurations across multiple FortiGate devices. In an SD-WAN deployment, templates can reduce repetitive work when configuring common settings such as interfaces, routing, VPNs, firewall policies, and SD-WAN parameters. This approach improves consistency and makes centralized administration easier. Device-specific values can be handled where required while common settings remain standardized. Templates are especially useful as the number of branches grows because administrators can manage a common configuration baseline instead of making identical changes individually on every FortiGate.

Question 354

Which Performance SLA measurement indicates that some packets did not successfully reach the destination?

  1. Latency
  2. Jitter
  3. Packet loss
  4. Bandwidth

Correct Answer: 3

Explanation

Packet loss represents packets that fail to successfully reach their destination. Excessive packet loss can seriously affect application performance because packets may need to be retransmitted, while real-time applications may experience interruptions or degraded quality. Performance SLA can monitor packet loss and compare the measured value against a configured threshold. If the threshold is exceeded, the member may fail the SLA for the relevant SD-WAN rule. Administrators should consider packet loss together with latency and jitter because a path with low delay can still be unsuitable if a significant percentage of packets are being lost.

Question 355

What is the primary purpose of an SD-WAN zone?

  1. To group SD-WAN interfaces or members for simplified policy and routing use
  2. To replace all firewall policies
  3. To store FortiAnalyzer logs
  4. To provide DNS resolution

Correct Answer: 1

Explanation

An SD-WAN zone can group SD-WAN members into a logical interface or zone that can be referenced more easily in routing and policy configurations. This abstraction simplifies administration because policies do not necessarily need to reference each physical or logical WAN member individually. The SD-WAN system can then make path-selection decisions among the members associated with the relevant configuration. Zones are particularly useful in environments with multiple WAN transports because the logical configuration can remain consistent even when the number or type of underlying members changes.

Question 356

Which SD-WAN rule criterion is most appropriate when steering traffic for a specific recognized Internet service?

  1. Source MAC address
  2. Internet Service Database
  3. Device hostname
  4. ARP entry

Correct Answer: 2

Explanation

The Internet Service Database can be used to identify recognized Internet services and their associated destinations. This allows administrators to create SD-WAN rules for specific services without manually maintaining all of their destination IP addresses. This is useful for cloud applications and Internet services that may use multiple or changing addresses. Once the traffic matches the relevant service, the SD-WAN rule can apply a selected strategy and Performance SLA requirements. ISDB-based matching can therefore simplify configuration while providing application or service-specific traffic steering across multiple WAN connections.

Question 357

What can happen when all SD-WAN members that match a rule fail its required Performance SLA conditions?

  1. The rule automatically creates a new WAN connection
  2. FortiAnalyzer changes the routing table
  3. No member may be eligible to carry the matching traffic under that rule
  4. The FortiGate disables all firewall policies

Correct Answer: 3

Explanation

If all members considered by an SD-WAN rule fail its required Performance SLA conditions, there may be no eligible member for that traffic according to the rule’s configured requirements. This can result in traffic not being forwarded through the expected SD-WAN path until a member becomes eligible again or the configuration changes. Administrators should therefore configure realistic SLA thresholds and provide appropriate backup paths where availability is critical. Troubleshooting should include checking health-check results, member status, routing, policies, and the actual SLA measurements to determine why no eligible path is available.

Question 358

Which distinction correctly describes an SD-WAN underlay and overlay?

  1. Underlay is the physical or transport network, while overlay is the logical network built across it
  2. Underlay is always an IPsec tunnel, while overlay is always a physical interface
  3. Underlay contains only firewall policies, while overlay contains only logs
  4. Underlay and overlay are identical terms

Correct Answer: 1

Explanation

The underlay refers to the underlying transport networks used to provide connectivity, such as broadband, MPLS, LTE, or other WAN services. The overlay is the logical connectivity established across those transports, often using technologies such as IPsec VPN tunnels. SD-WAN can use multiple underlay connections and select appropriate paths for traffic while maintaining secure overlay connectivity. Understanding this distinction is important when troubleshooting. A problem can occur in the physical or provider transport even when the overlay configuration is correct, or an overlay tunnel can fail even when the underlying WAN interface remains operational.

Question 359

Which SD-WAN strategy is designed to consider configured member cost when selecting an eligible path?

  1. Best Quality
  2. Manual
  3. Load Balance
  4. Lowest Cost (SLA)

Correct Answer: 4

Explanation

Lowest Cost (SLA) considers configured path cost while also evaluating Performance SLA requirements. This allows an organization to prefer a lower-cost WAN connection as long as it satisfies the required network-quality conditions. If that lower-cost path fails the applicable SLA, another eligible member can be selected. This approach can help organizations balance operational cost and application performance. Administrators should assign meaningful cost values and configure SLA thresholds that reflect the requirements of the applications being steered. The strategy is useful when multiple WAN providers have different pricing and performance characteristics.

Question 360

Which combination provides application-specific traffic steering while allowing FortiGate to react to WAN quality changes?

  1. Static NAT and DNS
  2. Application-aware SD-WAN rules and Performance SLA
  3. DHCP and ARP
  4. SMTP and SNMP

Correct Answer: 2

Explanation

Application-aware SD-WAN rules can identify specific applications and define how their traffic should be handled. Performance SLA then provides current measurements of WAN path quality, such as latency, jitter, packet loss, and reachability. Together, these features allow FortiGate to apply application-specific steering while adapting when network conditions change. For example, a business application can be assigned stricter quality requirements than ordinary Internet traffic. If its preferred WAN member fails those requirements, another eligible member can be selected according to the configured strategy. This provides dynamic traffic control rather than relying solely on static routing decisions.