View Full Fortinet NSE6_SDW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 361
Which SD-WAN component continuously evaluates the health of configured WAN paths?
- Performance SLA
- Firewall address group
- DNS server
- DHCP relay
Correct Answer: 1
Explanation
Performance SLA continuously evaluates configured WAN paths using health-check measurements. Depending on the configuration, FortiGate can monitor latency, jitter, packet loss, and reachability. The resulting measurements help determine whether an SD-WAN member is suitable for traffic governed by a particular rule. This allows path selection to adapt when network conditions change. For example, if a WAN connection develops excessive packet loss, it may fail the configured SLA and another eligible member can be selected. Performance SLA therefore provides the measurement mechanism that supports quality-based SD-WAN decisions rather than relying only on interface up or down status.
Question 362
A company wants voice traffic to use the WAN path with the lowest measured latency and jitter. Which strategy is most suitable?
- Manual
- Best Quality
- Load Balance
- Lowest Cost
Correct Answer: 2
Explanation
Best Quality is suitable when traffic should prefer a WAN path based on measured network performance. For voice traffic, latency and jitter are particularly important because excessive delay or variation can affect call quality. Performance SLA can monitor these values and determine whether available members satisfy configured requirements. FortiGate can then use the strategy to select an appropriate eligible path. Administrators should also consider packet loss because voice traffic can be affected by multiple quality problems. The goal is to ensure that the selected path meets the application’s requirements rather than simply choosing the cheapest or manually preferred connection.
Question 363
Which SD-WAN metric indicates that packets are being discarded before reaching their destination?
- Latency
- Jitter
- Packet loss
- Throughput
Correct Answer: 3
Explanation
Packet loss indicates that packets are not successfully reaching the destination. It is an important WAN-quality measurement because lost packets can cause retransmissions and degraded application performance. Real-time traffic such as voice and video can be especially sensitive to packet loss because retransmission may not be practical for time-sensitive data. Performance SLA can monitor packet loss and compare it against a configured threshold. If packet loss exceeds the acceptable value, the member can become unsuitable for a particular SD-WAN rule. Administrators should analyze packet loss together with latency and jitter to understand overall WAN quality.
Question 364
Which Fortinet product provides centralized management of multiple FortiGate devices?
- FortiAnalyzer
- FortiManager
- FortiMail
- FortiSandbox
Correct Answer: 2
Explanation
FortiManager provides centralized management for multiple FortiGate devices. It can help administrators maintain configurations, policies, objects, and other settings across distributed deployments. In an SD-WAN environment, centralized management becomes especially useful when many branches need similar configurations. Administrators can use FortiManager capabilities such as configuration templates and centralized provisioning to reduce repetitive work. FortiAnalyzer serves a different primary purpose by collecting and analyzing logs. Using both platforms together provides centralized configuration management as well as centralized visibility into network and security events.
Question 365
Which SD-WAN strategy can distribute traffic across multiple eligible WAN members?
- Load Balance
- Manual
- Best Quality
- Lowest Cost
Correct Answer: 1
Explanation
Load Balance can distribute traffic among multiple eligible SD-WAN members. This helps organizations make use of multiple WAN connections instead of depending entirely on one path. Eligibility can still depend on configured Performance SLA requirements, meaning a degraded member may be excluded from selection. The exact distribution behavior depends on the SD-WAN configuration and traffic characteristics. Administrators should consider link bandwidth, cost, reliability, and application requirements when choosing this strategy. Load balancing can be useful when several connections are intended to contribute to overall WAN capacity rather than operating strictly as primary and backup links.
Question 366
What is the primary purpose of an IPsec overlay in an SD-WAN architecture?
- To provide encrypted logical connectivity across WAN transports
- To replace all routing protocols
- To provide DNS resolution
- To collect FortiGate logs
Correct Answer: 1
Explanation
An IPsec overlay provides encrypted logical connectivity across underlying WAN transports. The underlay might consist of broadband, MPLS, LTE, or other available connections, while the IPsec tunnel provides protected communication between sites. SD-WAN can then evaluate these paths and steer traffic according to configured rules and Performance SLA requirements. Using an overlay allows organizations to maintain secure site-to-site connectivity while using multiple transport services. This architecture also supports redundancy because multiple tunnels or transport paths can be available. Troubleshooting should distinguish between an underlay connectivity problem and an IPsec overlay problem.
Question 367
Which protocol is commonly used for dynamic routing between large numbers of network sites?
- ARP
- DHCP
- BGP
- NTP
Correct Answer: 3
Explanation
BGP is commonly used for dynamic routing in large and complex network environments. It allows FortiGate devices to exchange network prefixes with routing peers and dynamically learn reachable destinations. This can reduce the administrative burden associated with maintaining large numbers of static routes. In SD-WAN deployments, BGP can provide routing information while SD-WAN rules handle application-aware traffic steering and path selection. Administrators can also apply routing policies to influence route advertisement and selection. BGP is therefore useful when an SD-WAN architecture needs scalable dynamic routing between hubs, branches, data centers, or other network domains.
Question 368
Which metric measures the variation in delay between successive packets?
- Latency
- Jitter
- Packet loss
- Throughput
Correct Answer: 2
Explanation
Jitter measures variation in packet delay. A WAN connection may have an acceptable average latency while still experiencing significant jitter. This can create problems for applications that require consistent packet timing, particularly voice and video. FortiGate can measure jitter through Performance SLA health checks when the relevant monitoring configuration is enabled. Administrators can define thresholds to determine whether a path remains suitable for specific traffic. If jitter exceeds the configured requirement, the path may fail the SLA for that SD-WAN rule. Jitter should therefore be evaluated separately from average latency when designing SD-WAN policies for real-time applications.
Question 369
Which feature allows an administrator to use recognized cloud or Internet services as an SD-WAN matching criterion?
- Internet Service Database
- ARP table
- DHCP scope
- DNS cache
Correct Answer: 1
Explanation
The Internet Service Database allows administrators to use predefined Internet services as traffic-matching criteria. Instead of manually maintaining large collections of destination IP addresses, administrators can use recognized service definitions when creating appropriate SD-WAN rules. This is useful for cloud applications and Internet services that may use multiple addresses or change their infrastructure over time. Once traffic matches the relevant service, the SD-WAN rule can apply the configured path-selection strategy and Performance SLA requirements. This simplifies administration and can make application-specific Internet traffic steering easier to maintain.
Question 370
Which topology connects branch sites primarily through one or more central hub locations?
- Full Mesh
- Hub-and-Spoke
- Ring
- Bus
Correct Answer: 2
Explanation
Hub-and-spoke connects branch sites through one or more central hub locations. Each branch, or spoke, normally establishes connectivity with the hub rather than maintaining direct connections to every other branch. This reduces the number of tunnels and can simplify centralized routing and security inspection. A disadvantage is that spoke-to-spoke traffic may need to pass through the hub, increasing latency and hub resource consumption. Fortinet ADVPN can help address this limitation by allowing dynamic shortcut paths between suitable spokes. SD-WAN can then apply path-selection policies across the available WAN connections.
Question 371
Which strategy allows administrators to explicitly define the preferred sequence of SD-WAN members?
- Lowest Cost
- Best Quality
- Load Balance
- Manual
Correct Answer: 4
Explanation
Manual strategy allows administrators to explicitly define the preferred order of SD-WAN members. This is useful when there is a known primary connection and one or more backup connections. For example, an organization may want a dedicated WAN circuit to be preferred while using broadband only when the primary link is unavailable or unsuitable. Performance SLA can still influence eligibility depending on configuration. Manual strategy provides predictable behavior, but administrators should understand that a fixed preference does not necessarily represent the best path under every network condition. It is most useful when explicit operational priorities are known.
Question 372
Which FortiAnalyzer capability is most useful when investigating historical SD-WAN connectivity events?
- Centralized log analysis
- Configuration template deployment
- IPsec key exchange
- WAN load balancing
Correct Answer: 1
Explanation
FortiAnalyzer provides centralized log collection and analysis, making it useful for investigating historical network and security events. In an SD-WAN environment, administrators can use centralized logs to examine events from multiple FortiGate devices and investigate connectivity behavior. This can help identify patterns involving link failures, policy activity, or other operational events. FortiManager, in contrast, focuses on centralized configuration and device management. FortiAnalyzer therefore complements FortiManager by providing operational visibility rather than being the primary platform for deploying configurations.
Question 373
What happens when a WAN member exceeds the packet-loss threshold configured for an applicable Performance SLA?
- Its cost automatically becomes zero
- It may fail the SLA and become ineligible for that rule
- FortiManager automatically deletes the member
- All other WAN members are disabled
Correct Answer: 2
Explanation
When packet loss exceeds the threshold configured for a Performance SLA, the WAN member may fail the SLA and become ineligible for traffic associated with that rule. This allows FortiGate to respond dynamically to degraded network conditions. If another member satisfies the rule’s requirements, the configured SD-WAN strategy can select that alternative path. The member itself is not necessarily removed from the SD-WAN configuration; its eligibility can change based on current measurements. Administrators should configure thresholds carefully because thresholds that are too strict can cause unnecessary switching, while thresholds that are too relaxed may allow poor-quality paths to remain active.
Question 374
Which feature can create dynamic shortcut connectivity between suitable ADVPN spokes?
- ADVPN
- DHCP
- DNS
- NAT
Correct Answer: 1
Explanation
ADVPN provides mechanisms for dynamic shortcut connectivity between suitable spokes. In a traditional hub-and-spoke architecture, traffic between branches can be forced through the hub even when a direct path would be more efficient. ADVPN can dynamically establish a shortcut when the required routing and VPN conditions are satisfied. This can reduce unnecessary traffic through the hub and potentially lower latency for branch-to-branch communication. ADVPN is commonly combined with IPsec overlays and dynamic routing. SD-WAN can then apply additional traffic-steering logic to available paths based on configured application and Performance SLA requirements.
Question 375
Which measurement is expressed as the delay experienced by network traffic?
- Jitter
- Packet loss
- Latency
- Throughput
Correct Answer: 3
Explanation
Latency represents the time delay experienced by network traffic between endpoints. High latency can make interactive applications feel slow and can negatively affect voice, video, remote desktop, and transactional services. Performance SLA can monitor latency and compare the measured value with configured thresholds. If the latency becomes unacceptable for a specific SD-WAN rule, the member can fail the applicable SLA and another eligible path may be selected. Latency does not indicate how much variation exists between packet delays; that is measured by jitter. Similarly, packet loss measures unsuccessful packet delivery rather than delay.
Question 376
Which SD-WAN rule criterion can identify traffic based on the application generating it?
- Application
- Destination MAC
- DHCP server
- Interface speed only
Correct Answer: 1
Explanation
The application criterion allows an SD-WAN rule to identify traffic according to the application generating or representing that traffic. This enables administrators to apply different path-selection policies to different applications. For example, real-time communications can receive stricter network-quality requirements than ordinary web browsing. Application-based matching can be combined with source, destination, service, or ISDB criteria to create more specific policies. Once traffic matches the rule, the configured SD-WAN strategy and Performance SLA conditions determine the eligible WAN members. This provides application-aware steering instead of treating all traffic identically.
Question 377
What is the main benefit of combining SD-WAN with multiple Internet connections?
- It allows traffic to be intelligently steered among available paths
- It guarantees identical latency on all links
- It removes the need for security policies
- It eliminates routing protocols
Correct Answer: 1
Explanation
Combining SD-WAN with multiple Internet connections allows FortiGate to intelligently steer traffic among available paths. Different applications can have different requirements, and SD-WAN rules can use criteria such as source, destination, application, or Internet service to classify traffic. Performance SLA can then evaluate path quality and determine which members remain eligible. This provides flexibility and resilience compared with using a single Internet connection. However, SD-WAN does not make all links identical or guarantee perfect performance. Effective results depend on correct routing, firewall policies, health checks, member configuration, and appropriate traffic-steering strategies.
Question 378
Which component provides the measurements used to determine whether a WAN member meets network-quality requirements?
- FortiAnalyzer reports only
- Performance SLA health checks
- DHCP leases
- Firewall address objects
Correct Answer: 2
Explanation
Performance SLA health checks provide the measurements used to evaluate WAN member quality. Depending on configuration, FortiGate can monitor reachability, latency, jitter, packet loss, and other relevant indicators. These results are compared against configured requirements to determine whether a member is eligible for traffic governed by an SD-WAN rule. This differs from simply checking whether an interface is physically up. A WAN interface can remain operational while experiencing poor latency or excessive packet loss. Performance SLA therefore gives SD-WAN more detailed information for making quality-aware path-selection decisions.
Question 379
Which FortiManager capability is especially useful when deploying the same SD-WAN baseline to many branch FortiGate devices?
- Configuration Templates
- Packet capture
- DNS filtering
- Web filtering
Correct Answer: 1
Explanation
Configuration Templates in FortiManager are useful for deploying standardized configurations across multiple FortiGate devices. An SD-WAN baseline may include common interfaces, VPN settings, routing, firewall policies, and SD-WAN rules. Rather than configuring every branch independently, administrators can maintain common settings centrally and apply them to multiple devices. This improves consistency and reduces configuration effort. Device-specific values can still be handled where required. Templates become increasingly valuable in large deployments because changes to a common configuration can be managed centrally instead of repeating the same administrative tasks across every branch.
Question 380
Which combination best supports dynamic selection of a WAN path for application-specific traffic?
- DNS and DHCP
- Static NAT and ARP
- SD-WAN rules, Performance SLA, and multiple WAN members
- SMTP and SNMP
Correct Answer: 3
Explanation
SD-WAN rules, Performance SLA, and multiple WAN members work together to provide dynamic path selection. SD-WAN rules classify traffic according to criteria such as application, source, destination, service, or Internet service. Performance SLA measures the quality of available members using metrics such as latency, jitter, packet loss, and reachability. Multiple WAN members provide the actual path choices. When traffic matches a rule, FortiGate can evaluate eligible members and apply the configured strategy to select an appropriate path. This architecture allows traffic steering to respond to both application requirements and changing WAN conditions rather than relying only on static routing.