View Full Fortinet NSE6_SDW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 381
Which SD-WAN feature allows FortiGate to evaluate whether a WAN path is meeting application-specific quality requirements?
- Performance SLA
- DHCP relay
- DNS forwarding
- ARP inspection
Correct Answer: 1
Explanation
Performance SLA allows FortiGate to evaluate the quality of WAN paths against configured requirements. Depending on the health-check configuration, FortiGate can measure latency, jitter, packet loss, and reachability. These measurements can then be used by SD-WAN rules to determine whether a member is suitable for particular traffic. This is important because an interface being physically up does not necessarily mean that the path is providing acceptable application performance. Performance SLA allows SD-WAN decisions to consider actual network conditions and can help move traffic toward another eligible member when the preferred path becomes degraded.
Question 382
An administrator wants normal web traffic to use several healthy WAN links instead of one fixed link. Which strategy should be considered?
- Manual
- Load Balance
- Best Quality
- Lowest Cost
Correct Answer: 2
Explanation
Load Balance can distribute traffic among multiple eligible SD-WAN members. This can help utilize several WAN connections instead of keeping most traffic on one fixed path. The available members can still be evaluated against Performance SLA requirements if the SD-WAN rule uses them. Load balancing is useful when an organization wants to take advantage of the combined availability of multiple connections. Administrators should consider bandwidth differences, provider characteristics, latency, and cost when designing the configuration. Critical applications may still require separate rules if they need specific quality guarantees or a particular path-selection strategy.
Question 383
Which SD-WAN metric is most directly associated with variation in packet delivery timing?
- Throughput
- Packet loss
- Latency
- Jitter
Correct Answer: 4
Explanation
Jitter represents variation in packet delivery timing. It is particularly important for real-time applications because inconsistent packet arrival can cause voice or video quality problems. A path can have relatively low average latency but still suffer from high jitter. FortiGate can monitor jitter through Performance SLA health checks and use the result when evaluating path eligibility. Administrators can configure an acceptable threshold based on application requirements. If the measured jitter exceeds the configured limit, the path may fail the applicable SLA and another eligible member can be selected according to the SD-WAN rule.
Question 384
Which Fortinet solution is primarily responsible for centralized FortiGate configuration management?
- FortiAnalyzer
- FortiManager
- FortiMail
- FortiWeb
Correct Answer: 2
Explanation
FortiManager provides centralized management and configuration capabilities for FortiGate devices. It is especially useful in distributed SD-WAN environments where many branches require similar configurations. Administrators can manage policies, objects, routing, VPN settings, and other configurations from a central platform. Configuration Templates can further simplify deployment of common settings across multiple devices. FortiAnalyzer has a different primary role focused on centralized log collection, analysis, and reporting. Using both products together can provide centralized configuration control through FortiManager and centralized operational visibility through FortiAnalyzer.
Question 385
What can happen if a Performance SLA detects excessive latency on the currently preferred WAN member?
- Another eligible member can be selected
- The FortiGate automatically deletes the interface
- All SD-WAN rules are removed
- FortiAnalyzer disables the WAN link
Correct Answer: 1
Explanation
If a preferred WAN member exceeds the latency threshold configured for the relevant Performance SLA, it can fail the SLA. If another member satisfies the requirements, the configured SD-WAN strategy can select that alternative path. The original interface is not necessarily removed or disabled; its eligibility can change according to current health-check results. This dynamic behavior is one of the main advantages of SD-WAN over relying only on static routing. Administrators should configure realistic thresholds so that temporary fluctuations do not cause unnecessary path changes while genuine degradation is still detected promptly.
Question 386
Which technology is commonly used to securely connect branch FortiGate devices over public Internet links?
- IPsec VPN
- DHCP
- ARP
- DNS
Correct Answer: 1
Explanation
IPsec VPN is commonly used to establish secure encrypted connectivity between FortiGate devices across public Internet connections. In an SD-WAN design, IPsec tunnels can form overlay paths across different underlay transports. Multiple tunnels can provide redundancy and additional traffic-steering options. SD-WAN can evaluate these paths using Performance SLA and select suitable paths according to configured rules. This architecture allows organizations to use lower-cost Internet services while maintaining protected communication between branches and other sites. Proper tunnel configuration, routing, firewall policies, and health checks are required for reliable operation.
Question 387
Which routing protocol can dynamically exchange network prefixes between FortiGate sites?
- DNS
- SNMP
- BGP
- DHCP
Correct Answer: 3
Explanation
BGP can dynamically exchange network prefixes between FortiGate devices and other routing peers. This is valuable in larger SD-WAN environments because manually maintaining routes for many sites can become difficult. BGP can advertise reachable networks and learn remote prefixes dynamically. SD-WAN then operates alongside the routing system to apply traffic-steering decisions based on rules and path quality. Administrators can use BGP policies to control route advertisements and preferences. This separation allows routing protocols to provide reachability information while SD-WAN focuses on selecting suitable paths for specific traffic.
Question 388
Which metric represents the percentage of packets that fail to reach their intended destination?
- Latency
- Packet loss
- Jitter
- Throughput
Correct Answer: 2
Explanation
Packet loss represents the percentage or amount of packets that fail to successfully reach the destination. Excessive packet loss can negatively affect application performance because lost packets may require retransmission, while real-time traffic may experience interruptions. FortiGate can monitor packet loss using Performance SLA health checks. Administrators can configure a threshold that determines when the path is considered unsuitable for a particular SD-WAN rule. Packet loss should not be confused with latency or jitter. Latency measures delay, while jitter measures variation in delay. Together, these metrics provide a more complete picture of WAN path quality.
Question 389
Which Fortinet database can simplify SD-WAN matching for recognized Internet applications and services?
- Internet Service Database
- ARP database
- DHCP database
- MAC address table
Correct Answer: 1
Explanation
The Internet Service Database provides predefined information about recognized Internet services and their destinations. SD-WAN rules can use this information to identify relevant traffic without requiring administrators to manually maintain every destination IP address. This can be particularly useful for cloud services that use multiple addresses or frequently change infrastructure. Once traffic matches the appropriate ISDB entry, the SD-WAN rule can apply its configured path-selection behavior. This approach simplifies administration and can make service-specific steering policies easier to maintain across large environments with multiple Internet-facing applications.
Question 390
Which topology normally requires a central hub for communication between branch sites when no direct shortcut exists?
- Full Mesh
- Point-to-Point
- Hub-and-Spoke
- Ring
Correct Answer: 3
Explanation
In a hub-and-spoke topology, branch sites normally communicate through one or more central hubs. A spoke generally maintains connectivity with the hub rather than having direct tunnels to every other spoke. As a result, traffic between two branches may travel through the hub when no direct shortcut is available. This design simplifies centralized management and security inspection but can increase latency and resource usage at the hub. ADVPN can help by creating dynamic shortcuts between suitable spokes. SD-WAN can then evaluate the available paths and apply traffic-steering policies according to application and network-quality requirements.
Question 391
Which SD-WAN strategy is useful when administrators want path selection to follow a predefined member preference?
- Best Quality
- Manual
- Load Balance
- Lowest Cost
Correct Answer: 2
Explanation
Manual strategy allows administrators to define a preferred order for SD-WAN members. This is useful when an organization has a primary WAN connection and one or more backup connections. The administrator can specify which member should normally be preferred and which should be used when the preferred path is unavailable or unsuitable. Performance SLA can still be used to determine whether a member meets required conditions. Manual selection provides predictable behavior but does not dynamically rank paths according to overall quality in the same way as quality-focused strategies. It is appropriate when explicit operational preference is required.
Question 392
Which measurement indicates the delay experienced by packets across a network path?
- Packet loss
- Jitter
- Latency
- Throughput
Correct Answer: 3
Explanation
Latency measures the delay experienced by packets as they travel between endpoints. High latency can negatively affect interactive applications because users experience slower responses. Applications such as voice, remote desktop, database transactions, and interactive web services can be sensitive to excessive delay. Performance SLA can measure latency and compare it against configured thresholds. If a member exceeds the acceptable value, it may fail the SLA for a particular SD-WAN rule. Latency should be considered together with packet loss and jitter because a path can have low latency while still suffering from other problems that affect application performance.
Question 393
Which FortiManager feature helps administrators deploy standardized settings to multiple FortiGate devices?
- Configuration Templates
- Packet Capture
- Traffic Shaping
- Antivirus Profiles
Correct Answer: 1
Explanation
Configuration Templates allow administrators to maintain standardized settings and deploy them across multiple FortiGate devices. This is particularly useful for SD-WAN deployments where branches often share common configurations. Templates can help reduce repetitive configuration tasks and improve consistency. Common settings may include interface configurations, VPN parameters, routing, firewall policies, and SD-WAN-related settings. Device-specific information can be handled separately where required. Centralized template management becomes increasingly valuable as the number of branches increases because administrators can make changes to common configurations centrally rather than manually modifying every FortiGate.
Question 394
Which SD-WAN strategy is designed to consider WAN member cost when selecting a suitable path?
- Best Quality
- Manual
- Load Balance
- Lowest Cost (SLA)
Correct Answer: 4
Explanation
Lowest Cost (SLA) considers the configured cost of WAN members while also taking Performance SLA requirements into account. This allows an organization to prefer a lower-cost path when it still provides acceptable network quality. If the low-cost member fails the required SLA conditions, another eligible member can be selected. This strategy can help organizations balance operational expenses with application performance. Administrators should configure realistic member costs and appropriate SLA thresholds. A very low-cost connection may not always be appropriate for sensitive applications if it consistently experiences excessive latency, jitter, or packet loss.
Question 395
Which FortiAnalyzer function helps administrators investigate network events across multiple FortiGate devices?
- Centralized log analysis
- Configuration template deployment
- IPsec tunnel negotiation
- SD-WAN path selection
Correct Answer: 1
Explanation
Centralized log analysis is a primary FortiAnalyzer function. FortiGate devices can send logs to FortiAnalyzer, allowing administrators to review events from multiple devices through a centralized system. In an SD-WAN deployment, this can help with troubleshooting connectivity issues, investigating security events, and reviewing historical activity. FortiAnalyzer does not primarily perform the SD-WAN path-selection process or deploy device configurations. Those responsibilities belong to FortiGate and FortiManager respectively. Centralized logging is particularly valuable when an organization has many branches and needs to correlate events across multiple FortiGate devices.
Question 396
Which SD-WAN rule criterion can be used to match traffic based on its destination network?
- Source address
- Destination address
- Application
- Internet Service Database
Correct Answer: 2
Explanation
Destination address allows an SD-WAN rule to identify traffic based on the network or address it is attempting to reach. This can be useful when different destinations require different WAN paths. For example, traffic destined for a corporate data center may need to use an IPsec overlay, while general Internet traffic can use a broadband connection. Destination-based matching can be combined with other criteria such as source address or application to make traffic steering more specific. Once traffic matches the rule, FortiGate evaluates eligible SD-WAN members according to the configured strategy and Performance SLA requirements.
Question 397
What is a key advantage of ADVPN in a large hub-and-spoke deployment?
- It can establish dynamic shortcuts between suitable spokes
- It removes the need for IPsec
- It disables routing between branches
- It forces all traffic through the hub
Correct Answer: 1
Explanation
ADVPN can establish dynamic shortcut connectivity between suitable spokes in a hub-and-spoke environment. Without shortcuts, traffic between two branch sites may need to travel through the central hub, which can increase latency and consume hub bandwidth and processing resources. Dynamic shortcuts can provide a more direct communication path when the required conditions are met. ADVPN is commonly deployed with IPsec and dynamic routing technologies. SD-WAN can then provide additional path-selection logic for traffic. This combination can improve scalability and efficiency in environments with many branches that need direct communication.
Question 398
Which metric would most directly indicate that a WAN path has inconsistent packet timing?
- Packet loss
- Latency
- Jitter
- Throughput
Correct Answer: 3
Explanation
Jitter indicates variation in packet timing across a network path. It is especially important for real-time applications because voice and video depend on relatively consistent packet delivery. A WAN link may show acceptable average latency while still experiencing significant jitter. Performance SLA can monitor jitter and compare it against configured thresholds. If the measured value exceeds the required level, the path may become unsuitable for traffic governed by the relevant SD-WAN rule. Administrators should evaluate jitter alongside packet loss and latency because no single metric completely represents WAN quality.
Question 399
What happens when an SD-WAN member fails the Performance SLA requirements for a specific rule while another member remains healthy?
- The failed member must be manually deleted
- The healthy member can be selected according to the configured strategy
- FortiAnalyzer automatically creates a VPN
- All WAN traffic is permanently blocked
Correct Answer: 2
Explanation
When an SD-WAN member fails the Performance SLA requirements for a specific rule, it can become ineligible for that rule. If another member satisfies the required conditions, FortiGate can select the healthy member according to the configured SD-WAN strategy. This allows traffic steering to adapt automatically to changing network conditions. The failed member does not necessarily need to be removed from the configuration because it may become eligible again when its performance improves. Administrators can monitor SLA measurements and logs to determine why a member became unsuitable and verify whether the alternate path is operating correctly.
Question 400
Which combination provides the core mechanism for application-aware, quality-based SD-WAN path selection?
- DHCP, DNS, and ARP
- NAT, SMTP, and SNMP
- Static routes, DNS, and DHCP
- SD-WAN rules, Performance SLA, and WAN members
Correct Answer: 4
Explanation
SD-WAN rules, Performance SLA, and WAN members work together to provide application-aware and quality-based path selection. SD-WAN rules classify traffic using criteria such as source, destination, application, service, or Internet Service Database. Performance SLA evaluates the quality of available WAN members using measurements such as latency, jitter, packet loss, and reachability. The WAN members provide the actual paths that can be selected. The configured strategy then determines how eligible members are used. This architecture allows FortiGate to adapt traffic forwarding to both application requirements and changing WAN conditions while maintaining centralized control over path-selection behavior.