Fortinet NSE6_SDW_AD-7.6 Practice Test Questions and Exam Dumps Part13 Q241-260

View Full Fortinet NSE6_SDW_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 241

Which SD-WAN feature allows FortiGate to evaluate whether a WAN path satisfies predefined performance requirements?

  1. Performance SLA
  2. DHCP Server
  3. DNS Filter
  4. Static NAT

Correct Answer: 1

Explanation

Performance SLA allows FortiGate to monitor WAN path quality against predefined requirements. Depending on the health-check configuration, FortiGate can measure latency, jitter, packet loss, and reachability. These measurements help determine whether an SD-WAN member is suitable for traffic governed by a particular rule. When a path no longer meets the required conditions, another eligible member can potentially be selected. Performance SLA therefore provides the measurement mechanism that supports dynamic SD-WAN decisions. Properly configured thresholds are important because overly strict values can unnecessarily exclude usable paths, while overly relaxed values may allow degraded links to remain active.

Question 242

An administrator wants voice traffic to use the WAN path with the lowest measured latency and jitter. Which SD-WAN strategy is most suitable?

  1. Manual
  2. Best Quality
  3. Load Balance
  4. Lowest Cost

Correct Answer: 2

Explanation

Best Quality is designed to select a suitable member based on measured path quality. For voice traffic, latency and jitter are important because excessive delay or variation can negatively affect call quality. By configuring an appropriate Performance SLA and applying it to the relevant SD-WAN rule, FortiGate can evaluate available members according to the required quality conditions. This is different from Lowest Cost, which emphasizes cost-related preference, or Manual, which provides fixed member preference. Administrators should establish realistic thresholds based on the application’s requirements and the expected characteristics of the available WAN services.

Question 243

Which SD-WAN rule matching criterion identifies traffic based on its destination network or address?

  1. Source address
  2. Destination address
  3. Administrator profile
  4. Interface speed

Correct Answer: 2

Explanation

Destination address can be used as a matching criterion in an SD-WAN rule to identify traffic based on where it is going. This is useful when different destinations require different WAN treatment. For example, traffic destined for a corporate data center can be assigned a specific SD-WAN strategy, while general Internet traffic can follow another rule. Destination-based matching can be combined with source, application, service, or Internet Service Database criteria. Once traffic matches the rule, FortiGate applies the configured steering behavior and evaluates eligible SD-WAN members according to the associated strategy and Performance SLA requirements.

Question 244

Which WAN performance metric represents the percentage of transmitted packets that do not successfully reach the destination?

  1. Latency
  2. Jitter
  3. Packet loss
  4. Throughput

Correct Answer: 3

Explanation

Packet loss represents packets that fail to successfully reach the destination during transmission. It is a key indicator of WAN reliability because lost packets can cause retransmissions, degraded application performance, and problems with real-time communications. Performance SLA can monitor packet loss and compare the result with configured thresholds. If the loss exceeds the acceptable level, the associated SD-WAN member may no longer satisfy the requirements of a rule. Packet loss differs from latency, which measures delay, and jitter, which measures variation in delay. Monitoring all relevant metrics provides a more complete picture of WAN path quality.

Question 245

Which FortiManager capability can help apply standardized SD-WAN configurations to multiple managed FortiGate devices?

  1. Configuration Templates
  2. Packet Capture
  3. Traffic Sniffer
  4. DNS Proxy

Correct Answer: 1

Explanation

Configuration Templates in FortiManager help administrators apply standardized configurations to multiple managed FortiGate devices. In an SD-WAN deployment, templates can help maintain consistent settings for interfaces, routing, VPNs, firewall policies, and SD-WAN-related configurations. This reduces the need to configure each branch manually and can improve operational consistency. Device-specific values can be adjusted when necessary. Centralized template management is particularly useful as the number of branches grows. Administrators can create a common baseline while still accommodating differences between individual sites, making large-scale SD-WAN deployment easier to manage.

Question 246

What is the primary role of an IPsec tunnel in an SD-WAN overlay?

  1. Assign IP addresses to users
  2. Provide encrypted logical connectivity between endpoints
  3. Resolve domain names
  4. Monitor CPU utilization

Correct Answer: 2

Explanation

An IPsec tunnel can provide secure, encrypted logical connectivity between FortiGate endpoints and is commonly used as part of an SD-WAN overlay. The underlying transport may be Internet, MPLS, LTE, or another WAN service. IPsec protects traffic across the transport while allowing the overlay to provide connectivity between sites. SD-WAN can then evaluate different paths and steer traffic according to rules and Performance SLA results. This separation between secure overlay connectivity and physical underlay transport allows organizations to use multiple WAN services while maintaining consistent logical communication between network locations.

Question 247

Which metric measures variation in packet delay rather than the average delay itself?

  1. Jitter
  2. Latency
  3. Packet loss
  4. Throughput

Correct Answer: 1

Explanation

Jitter measures variation in packet delay, while latency measures the delay itself. A network path may have acceptable average latency but still experience significant jitter if packets arrive with inconsistent timing. This can be particularly harmful to voice and video applications because those applications depend on relatively consistent packet delivery. FortiGate can measure jitter through Performance SLA health checks and use the results during SD-WAN path evaluation. Administrators should therefore consider both latency and jitter when designing SD-WAN policies for real-time applications. Appropriate SLA thresholds help identify paths that provide consistent service quality.

Question 248

Which Fortinet product is primarily responsible for centralized logging and reporting rather than device configuration management?

  1. FortiManager
  2. FortiAnalyzer
  3. FortiGate
  4. FortiSwitch

Correct Answer: 2

Explanation

FortiAnalyzer is primarily used for centralized log collection, analysis, reporting, and monitoring. In an SD-WAN environment, FortiAnalyzer can receive logs from multiple FortiGate devices and provide administrators with centralized visibility into network and security events. This can assist with troubleshooting path changes, connectivity problems, and traffic behavior. FortiManager serves a different primary purpose by providing centralized device and configuration management. Using the two products together can provide both centralized configuration control and centralized operational visibility across a distributed Fortinet SD-WAN environment.

Question 249

Which SD-WAN strategy is intended to distribute traffic among multiple eligible WAN members?

  1. Best Quality
  2. Manual
  3. Load Balance
  4. Lowest Cost

Correct Answer: 3

Explanation

Load Balance is intended to distribute traffic among multiple eligible SD-WAN members rather than concentrating all traffic on one preferred path. This can improve utilization when several WAN links are available and satisfy the applicable conditions. The exact distribution behavior depends on the configured strategy and FortiOS implementation. Performance SLA can still determine whether a member is eligible when SLA conditions are configured. Load balancing can be useful in environments with multiple Internet or WAN connections where administrators want to use available capacity efficiently instead of leaving secondary links mostly unused.

Question 250

Which topology connects multiple branch sites through one or more central hub locations?

  1. Full Mesh
  2. Hub-and-Spoke
  3. Ring
  4. Point-to-Point

Correct Answer: 2

Explanation

A hub-and-spoke topology connects multiple branch or spoke sites through one or more central hub locations. This design can simplify centralized routing, security inspection, and management. One potential limitation is that branch-to-branch traffic may have to travel through the hub, which can introduce additional latency and consume hub resources. Fortinet technologies such as ADVPN can provide dynamic shortcut connectivity when appropriate. SD-WAN can also be deployed across hub-and-spoke environments to select suitable paths according to application requirements and WAN conditions.

Question 251

Which routing protocol can dynamically advertise network prefixes between FortiGate devices in an SD-WAN deployment?

  1. BGP
  2. ARP
  3. ICMP
  4. DHCP

Correct Answer: 1

Explanation

BGP can dynamically advertise and learn network prefixes between FortiGate devices and other routing peers. It is useful in larger SD-WAN deployments because administrators do not need to manually configure every route. BGP can operate across suitable IPsec overlay connections and can be combined with SD-WAN for traffic steering. Routing policies can control route advertisements, filtering, and preference. The exact BGP design depends on the topology and organizational requirements. Proper configuration is important because incorrect route advertisements can lead to unexpected forwarding behavior or routing loops.

Question 252

Which feature can identify predefined cloud or Internet services for use in SD-WAN traffic matching?

  1. Internet Service Database
  2. DHCP Relay
  3. ARP Table
  4. DNS Cache

Correct Answer: 1

Explanation

The Internet Service Database, or ISDB, provides predefined information about recognized Internet services and their associated destinations. SD-WAN rules can use ISDB entries to identify traffic destined for supported services without requiring administrators to manually maintain every destination address. This is particularly useful for cloud applications and Internet-based services whose infrastructure may involve many addresses. Administrators can create traffic-steering rules around recognized services and combine them with Performance SLA conditions. This approach can simplify policy management and make application-specific WAN steering more practical in environments with frequently changing Internet destinations.

Question 253

What should happen to an SD-WAN member when its monitored path fails the required SLA threshold?

  1. It may become ineligible for traffic governed by that SLA
  2. The FortiGate must reboot
  3. All firewall policies are removed
  4. Every WAN interface is disabled

Correct Answer: 1

Explanation

When an SD-WAN member fails the Performance SLA requirements associated with a rule, it may become ineligible for traffic governed by that SLA. For example, excessive latency, packet loss, or jitter can cause a member to fail the configured threshold. If another member satisfies the required conditions, FortiGate can select that member according to the SD-WAN strategy. This provides dynamic failover without requiring the administrator to manually change routes every time a WAN path degrades. The physical interface does not necessarily shut down; its eligibility for specific SD-WAN traffic is what changes.

Question 254

Which component represents the physical WAN service that participates as an individual path in SD-WAN?

  1. SD-WAN member
  2. FortiAnalyzer report
  3. Firewall address group
  4. User authentication profile

Correct Answer: 1

Explanation

An SD-WAN member represents an individual WAN interface or logical path participating in SD-WAN. Examples can include Internet interfaces, MPLS connections, or other suitable WAN paths. FortiGate evaluates these members using SD-WAN rules, strategies, and Performance SLA information. A member can have attributes such as cost or priority that influence path selection. Understanding the concept of members is fundamental to SD-WAN because traffic is ultimately forwarded through one of the eligible members. If a member becomes unavailable or fails required SLA conditions, another eligible path can potentially be selected.

Question 255

Which architecture separates WAN transport connectivity from the logical tunnels built across those transports?

  1. Security profile and policy
  2. Underlay and overlay
  3. User and administrator
  4. DNS and DHCP

Correct Answer: 2

Explanation

The underlay and overlay architecture separates physical WAN transport from logical network connectivity. The underlay can consist of Internet, MPLS, broadband, LTE, or other transport services. The overlay can use IPsec tunnels or other logical connectivity mechanisms across those transports. SD-WAN can evaluate the available paths and steer traffic based on configured rules and network conditions. This architecture provides flexibility because organizations can change or add WAN transports without necessarily redesigning their logical network. Troubleshooting also becomes easier because administrators can determine whether a problem originates in the underlay or overlay.

Question 256

Which SD-WAN rule criterion is useful when traffic from different internal departments needs different WAN treatment?

  1. Source address
  2. Packet size only
  3. Device temperature
  4. System uptime

Correct Answer: 1

Explanation

Source address can identify traffic originating from different internal networks or departments. Administrators can use this criterion to create separate SD-WAN rules for different user groups or business units. For example, traffic from a finance department could receive stricter SLA requirements than general Internet traffic. The rule can then apply an appropriate SD-WAN strategy and evaluate eligible members. Source-based steering can also be combined with destination, application, or service criteria for more granular control. This provides a flexible method for aligning WAN behavior with organizational structure and application requirements.

Question 257

Which SD-WAN strategy considers path cost while also requiring acceptable Performance SLA results?

  1. Best Quality
  2. Load Balance
  3. Lowest Cost (SLA)
  4. Manual

Correct Answer: 3

Explanation

Lowest Cost (SLA) is designed to consider WAN member cost while also taking Performance SLA requirements into account. This allows administrators to prefer less expensive WAN services when those services still provide acceptable performance. If a low-cost member fails the required SLA conditions, another eligible member can be selected. This approach can help organizations balance operational cost and application quality. Accurate member cost values and realistic SLA thresholds are important for predictable results. The strategy is particularly useful when an organization has multiple WAN transports with different pricing structures and wants to use cheaper services whenever performance remains acceptable.

Question 258

Which Fortinet technology can dynamically establish shortcuts between spoke sites in an appropriate ADVPN deployment?

  1. ADVPN
  2. FortiAnalyzer
  3. FortiManager
  4. DHCP

Correct Answer: 1

Explanation

ADVPN is designed to support dynamic shortcut connectivity between spoke sites in suitable hub-and-spoke deployments. Without a shortcut, traffic between two spokes may need to traverse a central hub. This can increase latency and consume additional hub bandwidth. ADVPN can allow a more direct tunnel to be established when the configuration and routing environment support it. Fortinet deployments can combine ADVPN with IPsec, dynamic routing, and SD-WAN technologies. The resulting architecture can provide scalable connectivity while reducing unnecessary traffic hairpinning through centralized locations.

Question 259

Which measurement describes the time taken for packets to travel across a monitored WAN path?

  1. Jitter
  2. Latency
  3. Packet loss
  4. Throughput

Correct Answer: 2

Explanation

Latency describes the delay experienced by packets while traveling between endpoints across a network path. It is an important Performance SLA metric because high latency can negatively affect interactive applications such as voice, video conferencing, remote desktop, and transactional systems. FortiGate can monitor latency and compare it with configured thresholds. If the measured value exceeds the requirement, the affected member may become unsuitable for a particular SD-WAN rule. Latency should be considered alongside jitter and packet loss because a path with low latency can still provide poor application performance if it experiences significant loss or timing variation.

Question 260

Which combination provides application-based traffic steering while considering real-time WAN path quality?

  1. DHCP and ARP
  2. Application-aware SD-WAN rules and Performance SLA
  3. DNS and NTP
  4. SNMP and MAC learning

Correct Answer: 2

Explanation

Application-aware SD-WAN rules combined with Performance SLA allow FortiGate to make traffic-steering decisions based on both application identity and current WAN conditions. The rule identifies the relevant application and defines how its traffic should be handled. Performance SLA then evaluates available members using measurements such as latency, jitter, packet loss, or reachability. If a preferred path becomes degraded, another eligible member can be selected according to the configured strategy. This approach allows administrators to give business-critical applications different WAN treatment while still adapting to changing network conditions instead of relying only on static routes.