Fortinet NSE6_SDW_AD-7.6 Practice Test Questions and Exam Dumps Part19 Q361-380

View Full Fortinet NSE6_SDW_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 361

Which SD-WAN component continuously evaluates the health of configured WAN paths?

  1. Performance SLA
  2. Firewall address group
  3. DNS server
  4. DHCP relay

Correct Answer: 1

Explanation

Performance SLA continuously evaluates configured WAN paths using health-check measurements. Depending on the configuration, FortiGate can monitor latency, jitter, packet loss, and reachability. The resulting measurements help determine whether an SD-WAN member is suitable for traffic governed by a particular rule. This allows path selection to adapt when network conditions change. For example, if a WAN connection develops excessive packet loss, it may fail the configured SLA and another eligible member can be selected. Performance SLA therefore provides the measurement mechanism that supports quality-based SD-WAN decisions rather than relying only on interface up or down status.

Question 362

A company wants voice traffic to use the WAN path with the lowest measured latency and jitter. Which strategy is most suitable?

  1. Manual
  2. Best Quality
  3. Load Balance
  4. Lowest Cost

Correct Answer: 2

Explanation

Best Quality is suitable when traffic should prefer a WAN path based on measured network performance. For voice traffic, latency and jitter are particularly important because excessive delay or variation can affect call quality. Performance SLA can monitor these values and determine whether available members satisfy configured requirements. FortiGate can then use the strategy to select an appropriate eligible path. Administrators should also consider packet loss because voice traffic can be affected by multiple quality problems. The goal is to ensure that the selected path meets the application’s requirements rather than simply choosing the cheapest or manually preferred connection.

Question 363

Which SD-WAN metric indicates that packets are being discarded before reaching their destination?

  1. Latency
  2. Jitter
  3. Packet loss
  4. Throughput

Correct Answer: 3

Explanation

Packet loss indicates that packets are not successfully reaching the destination. It is an important WAN-quality measurement because lost packets can cause retransmissions and degraded application performance. Real-time traffic such as voice and video can be especially sensitive to packet loss because retransmission may not be practical for time-sensitive data. Performance SLA can monitor packet loss and compare it against a configured threshold. If packet loss exceeds the acceptable value, the member can become unsuitable for a particular SD-WAN rule. Administrators should analyze packet loss together with latency and jitter to understand overall WAN quality.

Question 364

Which Fortinet product provides centralized management of multiple FortiGate devices?

  1. FortiAnalyzer
  2. FortiManager
  3. FortiMail
  4. FortiSandbox

Correct Answer: 2

Explanation

FortiManager provides centralized management for multiple FortiGate devices. It can help administrators maintain configurations, policies, objects, and other settings across distributed deployments. In an SD-WAN environment, centralized management becomes especially useful when many branches need similar configurations. Administrators can use FortiManager capabilities such as configuration templates and centralized provisioning to reduce repetitive work. FortiAnalyzer serves a different primary purpose by collecting and analyzing logs. Using both platforms together provides centralized configuration management as well as centralized visibility into network and security events.

Question 365

Which SD-WAN strategy can distribute traffic across multiple eligible WAN members?

  1. Load Balance
  2. Manual
  3. Best Quality
  4. Lowest Cost

Correct Answer: 1

Explanation

Load Balance can distribute traffic among multiple eligible SD-WAN members. This helps organizations make use of multiple WAN connections instead of depending entirely on one path. Eligibility can still depend on configured Performance SLA requirements, meaning a degraded member may be excluded from selection. The exact distribution behavior depends on the SD-WAN configuration and traffic characteristics. Administrators should consider link bandwidth, cost, reliability, and application requirements when choosing this strategy. Load balancing can be useful when several connections are intended to contribute to overall WAN capacity rather than operating strictly as primary and backup links.

Question 366

What is the primary purpose of an IPsec overlay in an SD-WAN architecture?

  1. To provide encrypted logical connectivity across WAN transports
  2. To replace all routing protocols
  3. To provide DNS resolution
  4. To collect FortiGate logs

Correct Answer: 1

Explanation

An IPsec overlay provides encrypted logical connectivity across underlying WAN transports. The underlay might consist of broadband, MPLS, LTE, or other available connections, while the IPsec tunnel provides protected communication between sites. SD-WAN can then evaluate these paths and steer traffic according to configured rules and Performance SLA requirements. Using an overlay allows organizations to maintain secure site-to-site connectivity while using multiple transport services. This architecture also supports redundancy because multiple tunnels or transport paths can be available. Troubleshooting should distinguish between an underlay connectivity problem and an IPsec overlay problem.

Question 367

Which protocol is commonly used for dynamic routing between large numbers of network sites?

  1. ARP
  2. DHCP
  3. BGP
  4. NTP

Correct Answer: 3

Explanation

BGP is commonly used for dynamic routing in large and complex network environments. It allows FortiGate devices to exchange network prefixes with routing peers and dynamically learn reachable destinations. This can reduce the administrative burden associated with maintaining large numbers of static routes. In SD-WAN deployments, BGP can provide routing information while SD-WAN rules handle application-aware traffic steering and path selection. Administrators can also apply routing policies to influence route advertisement and selection. BGP is therefore useful when an SD-WAN architecture needs scalable dynamic routing between hubs, branches, data centers, or other network domains.

Question 368

Which metric measures the variation in delay between successive packets?

  1. Latency
  2. Jitter
  3. Packet loss
  4. Throughput

Correct Answer: 2

Explanation

Jitter measures variation in packet delay. A WAN connection may have an acceptable average latency while still experiencing significant jitter. This can create problems for applications that require consistent packet timing, particularly voice and video. FortiGate can measure jitter through Performance SLA health checks when the relevant monitoring configuration is enabled. Administrators can define thresholds to determine whether a path remains suitable for specific traffic. If jitter exceeds the configured requirement, the path may fail the SLA for that SD-WAN rule. Jitter should therefore be evaluated separately from average latency when designing SD-WAN policies for real-time applications.

Question 369

Which feature allows an administrator to use recognized cloud or Internet services as an SD-WAN matching criterion?

  1. Internet Service Database
  2. ARP table
  3. DHCP scope
  4. DNS cache

Correct Answer: 1

Explanation

The Internet Service Database allows administrators to use predefined Internet services as traffic-matching criteria. Instead of manually maintaining large collections of destination IP addresses, administrators can use recognized service definitions when creating appropriate SD-WAN rules. This is useful for cloud applications and Internet services that may use multiple addresses or change their infrastructure over time. Once traffic matches the relevant service, the SD-WAN rule can apply the configured path-selection strategy and Performance SLA requirements. This simplifies administration and can make application-specific Internet traffic steering easier to maintain.

Question 370

Which topology connects branch sites primarily through one or more central hub locations?

  1. Full Mesh
  2. Hub-and-Spoke
  3. Ring
  4. Bus

Correct Answer: 2

Explanation

Hub-and-spoke connects branch sites through one or more central hub locations. Each branch, or spoke, normally establishes connectivity with the hub rather than maintaining direct connections to every other branch. This reduces the number of tunnels and can simplify centralized routing and security inspection. A disadvantage is that spoke-to-spoke traffic may need to pass through the hub, increasing latency and hub resource consumption. Fortinet ADVPN can help address this limitation by allowing dynamic shortcut paths between suitable spokes. SD-WAN can then apply path-selection policies across the available WAN connections.

Question 371

Which strategy allows administrators to explicitly define the preferred sequence of SD-WAN members?

  1. Lowest Cost
  2. Best Quality
  3. Load Balance
  4. Manual

Correct Answer: 4

Explanation

Manual strategy allows administrators to explicitly define the preferred order of SD-WAN members. This is useful when there is a known primary connection and one or more backup connections. For example, an organization may want a dedicated WAN circuit to be preferred while using broadband only when the primary link is unavailable or unsuitable. Performance SLA can still influence eligibility depending on configuration. Manual strategy provides predictable behavior, but administrators should understand that a fixed preference does not necessarily represent the best path under every network condition. It is most useful when explicit operational priorities are known.

Question 372

Which FortiAnalyzer capability is most useful when investigating historical SD-WAN connectivity events?

  1. Centralized log analysis
  2. Configuration template deployment
  3. IPsec key exchange
  4. WAN load balancing

Correct Answer: 1

Explanation

FortiAnalyzer provides centralized log collection and analysis, making it useful for investigating historical network and security events. In an SD-WAN environment, administrators can use centralized logs to examine events from multiple FortiGate devices and investigate connectivity behavior. This can help identify patterns involving link failures, policy activity, or other operational events. FortiManager, in contrast, focuses on centralized configuration and device management. FortiAnalyzer therefore complements FortiManager by providing operational visibility rather than being the primary platform for deploying configurations.

Question 373

What happens when a WAN member exceeds the packet-loss threshold configured for an applicable Performance SLA?

  1. Its cost automatically becomes zero
  2. It may fail the SLA and become ineligible for that rule
  3. FortiManager automatically deletes the member
  4. All other WAN members are disabled

Correct Answer: 2

Explanation

When packet loss exceeds the threshold configured for a Performance SLA, the WAN member may fail the SLA and become ineligible for traffic associated with that rule. This allows FortiGate to respond dynamically to degraded network conditions. If another member satisfies the rule’s requirements, the configured SD-WAN strategy can select that alternative path. The member itself is not necessarily removed from the SD-WAN configuration; its eligibility can change based on current measurements. Administrators should configure thresholds carefully because thresholds that are too strict can cause unnecessary switching, while thresholds that are too relaxed may allow poor-quality paths to remain active.

Question 374

Which feature can create dynamic shortcut connectivity between suitable ADVPN spokes?

  1. ADVPN
  2. DHCP
  3. DNS
  4. NAT

Correct Answer: 1

Explanation

ADVPN provides mechanisms for dynamic shortcut connectivity between suitable spokes. In a traditional hub-and-spoke architecture, traffic between branches can be forced through the hub even when a direct path would be more efficient. ADVPN can dynamically establish a shortcut when the required routing and VPN conditions are satisfied. This can reduce unnecessary traffic through the hub and potentially lower latency for branch-to-branch communication. ADVPN is commonly combined with IPsec overlays and dynamic routing. SD-WAN can then apply additional traffic-steering logic to available paths based on configured application and Performance SLA requirements.

Question 375

Which measurement is expressed as the delay experienced by network traffic?

  1. Jitter
  2. Packet loss
  3. Latency
  4. Throughput

Correct Answer: 3

Explanation

Latency represents the time delay experienced by network traffic between endpoints. High latency can make interactive applications feel slow and can negatively affect voice, video, remote desktop, and transactional services. Performance SLA can monitor latency and compare the measured value with configured thresholds. If the latency becomes unacceptable for a specific SD-WAN rule, the member can fail the applicable SLA and another eligible path may be selected. Latency does not indicate how much variation exists between packet delays; that is measured by jitter. Similarly, packet loss measures unsuccessful packet delivery rather than delay.

Question 376

Which SD-WAN rule criterion can identify traffic based on the application generating it?

  1. Application
  2. Destination MAC
  3. DHCP server
  4. Interface speed only

Correct Answer: 1

Explanation

The application criterion allows an SD-WAN rule to identify traffic according to the application generating or representing that traffic. This enables administrators to apply different path-selection policies to different applications. For example, real-time communications can receive stricter network-quality requirements than ordinary web browsing. Application-based matching can be combined with source, destination, service, or ISDB criteria to create more specific policies. Once traffic matches the rule, the configured SD-WAN strategy and Performance SLA conditions determine the eligible WAN members. This provides application-aware steering instead of treating all traffic identically.

Question 377

What is the main benefit of combining SD-WAN with multiple Internet connections?

  1. It allows traffic to be intelligently steered among available paths
  2. It guarantees identical latency on all links
  3. It removes the need for security policies
  4. It eliminates routing protocols

Correct Answer: 1

Explanation

Combining SD-WAN with multiple Internet connections allows FortiGate to intelligently steer traffic among available paths. Different applications can have different requirements, and SD-WAN rules can use criteria such as source, destination, application, or Internet service to classify traffic. Performance SLA can then evaluate path quality and determine which members remain eligible. This provides flexibility and resilience compared with using a single Internet connection. However, SD-WAN does not make all links identical or guarantee perfect performance. Effective results depend on correct routing, firewall policies, health checks, member configuration, and appropriate traffic-steering strategies.

Question 378

Which component provides the measurements used to determine whether a WAN member meets network-quality requirements?

  1. FortiAnalyzer reports only
  2. Performance SLA health checks
  3. DHCP leases
  4. Firewall address objects

Correct Answer: 2

Explanation

Performance SLA health checks provide the measurements used to evaluate WAN member quality. Depending on configuration, FortiGate can monitor reachability, latency, jitter, packet loss, and other relevant indicators. These results are compared against configured requirements to determine whether a member is eligible for traffic governed by an SD-WAN rule. This differs from simply checking whether an interface is physically up. A WAN interface can remain operational while experiencing poor latency or excessive packet loss. Performance SLA therefore gives SD-WAN more detailed information for making quality-aware path-selection decisions.

Question 379

Which FortiManager capability is especially useful when deploying the same SD-WAN baseline to many branch FortiGate devices?

  1. Configuration Templates
  2. Packet capture
  3. DNS filtering
  4. Web filtering

Correct Answer: 1

Explanation

Configuration Templates in FortiManager are useful for deploying standardized configurations across multiple FortiGate devices. An SD-WAN baseline may include common interfaces, VPN settings, routing, firewall policies, and SD-WAN rules. Rather than configuring every branch independently, administrators can maintain common settings centrally and apply them to multiple devices. This improves consistency and reduces configuration effort. Device-specific values can still be handled where required. Templates become increasingly valuable in large deployments because changes to a common configuration can be managed centrally instead of repeating the same administrative tasks across every branch.

Question 380

Which combination best supports dynamic selection of a WAN path for application-specific traffic?

  1. DNS and DHCP
  2. Static NAT and ARP
  3. SD-WAN rules, Performance SLA, and multiple WAN members
  4. SMTP and SNMP

Correct Answer: 3

Explanation

SD-WAN rules, Performance SLA, and multiple WAN members work together to provide dynamic path selection. SD-WAN rules classify traffic according to criteria such as application, source, destination, service, or Internet service. Performance SLA measures the quality of available members using metrics such as latency, jitter, packet loss, and reachability. Multiple WAN members provide the actual path choices. When traffic matches a rule, FortiGate can evaluate eligible members and apply the configured strategy to select an appropriate path. This architecture allows traffic steering to respond to both application requirements and changing WAN conditions rather than relying only on static routing.