Fortinet NSE6_SDW_AD-7.6 Practice Test Questions and Exam Dumps Part7 Q121-140

View Full Fortinet NSE6_SDW_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 121

Which FortiGate component is responsible for defining traffic-steering behavior across SD-WAN members?

  1. FortiAnalyzer
  2. SD-WAN rule
  3. DHCP server
  4. DNS filter

Correct Answer: 2

Explanation

An SD-WAN rule defines how matching traffic should be handled across available SD-WAN members. The rule can identify traffic using criteria such as source address, destination address, application, service, or Internet Service Database information. After matching traffic, the rule applies a configured strategy to determine the preferred path. Performance SLA results can also influence which members are considered eligible. This allows administrators to create different forwarding behavior for different applications and destinations. For example, business-critical applications can be assigned higher-quality WAN paths while less-sensitive traffic can use other available connections.

Question 122

Which SD-WAN metric measures variation in packet delivery delay?

  1. Packet loss
  2. Latency
  3. Throughput
  4. Jitter

Correct Answer: 4

Explanation

Jitter represents variation in packet delay over a monitored network path. While latency describes the amount of delay experienced by packets, jitter describes how that delay changes from packet to packet. This distinction is particularly important for real-time applications such as voice and video. High jitter can cause audio distortion, video interruptions, or inconsistent playback. FortiGate Performance SLA can monitor jitter and compare it against configured thresholds. SD-WAN rules can then use this information when determining whether a particular WAN member is suitable for traffic that has strict timing requirements.

Question 123

What is the primary purpose of a Performance SLA target in FortiGate SD-WAN?

  1. To assign administrator privileges
  2. To configure firewall authentication
  3. To provide an endpoint for measuring WAN path quality
  4. To create a DHCP reservation

Correct Answer: 3

Explanation

A Performance SLA target provides an endpoint that FortiGate can use to evaluate WAN path quality. FortiGate sends health-check probes toward the configured target and measures characteristics such as latency, jitter, packet loss, and reachability, depending on the configuration. These results help determine whether an SD-WAN member meets the requirements associated with a particular rule. Selecting an appropriate target is important because the target should provide a meaningful representation of the service or destination being evaluated. Performance SLA monitoring therefore gives SD-WAN dynamic information for making path-selection decisions.

Question 124

Which technology commonly provides encrypted overlay connectivity between FortiGate devices?

  1. DHCP
  2. IPsec VPN
  3. DNS
  4. NTP

Correct Answer: 2

Explanation

IPsec VPN is commonly used to create encrypted overlay connections between FortiGate devices. In SD-WAN environments, IPsec tunnels can operate across different WAN transports such as broadband, MPLS, or other Internet connections. These tunnels provide secure logical connectivity while SD-WAN determines how traffic should use available paths. Multiple IPsec tunnels can also provide redundancy and different forwarding options between sites. This separation between underlay connectivity and overlay tunnels allows organizations to use several WAN services while maintaining secure communication. Proper routing, tunnel configuration, and SD-WAN policies are required for effective operation.

Question 125

Which SD-WAN strategy is primarily intended to distribute traffic among eligible WAN members?

  1. Best Quality
  2. Lowest Cost
  3. Manual
  4. Load Balance

Correct Answer: 4

Explanation

The Load Balance strategy is designed to distribute traffic across multiple eligible SD-WAN members. Instead of always selecting a single preferred path, FortiGate can make use of several suitable WAN connections. This can improve utilization of available bandwidth and prevent one link from carrying all traffic when other links are available. The actual distribution behavior depends on the SD-WAN configuration and matching traffic. Load balancing is different from Best Quality, which focuses more directly on performance measurements. Administrators should select the strategy according to application requirements, WAN capacity, cost, and desired resilience.

Question 126

Which protocol can be used for dynamic routing across an SD-WAN overlay?

  1. FTP
  2. BGP
  3. SMTP
  4. DHCP

Correct Answer: 2

Explanation

BGP can be used to exchange routing information dynamically across an SD-WAN overlay. Dynamic routing becomes particularly useful when a deployment contains many branches and manually maintaining routes would become difficult. BGP can advertise reachable networks between FortiGate devices and automatically update routing information when network conditions or topology change. In Fortinet environments, BGP can operate across IPsec overlays and work alongside SD-WAN functionality. The exact implementation depends on the network design, routing requirements, hub-and-spoke architecture, and addressing plan. Proper route filtering and policy design are important when using BGP.

Question 127

What can happen when an SD-WAN member exceeds its configured packet-loss SLA threshold?

  1. It automatically receives more traffic
  2. All firewall policies are removed
  3. It can become ineligible for traffic using that SLA
  4. FortiGate automatically shuts down

Correct Answer: 3

Explanation

When packet loss exceeds the threshold defined for a Performance SLA, the affected SD-WAN member can become unsuitable for traffic governed by that SLA. FortiGate continuously evaluates monitored WAN paths and compares measured performance against configured thresholds. If another member satisfies the required conditions, traffic can potentially be directed through that alternative path. This provides dynamic failover without requiring administrators to manually modify routing every time a WAN connection experiences degradation. The exact behavior depends on the SD-WAN rule, configured strategy, SLA requirements, and availability of alternative members.

Question 128

Which Fortinet product is primarily used for centralized log collection and analysis?

  1. FortiManager
  2. FortiGate
  3. FortiSwitch
  4. FortiAnalyzer

Correct Answer: 4

Explanation

FortiAnalyzer is designed primarily for centralized log collection, analysis, reporting, and monitoring. FortiGate devices can send logs to FortiAnalyzer, allowing administrators to investigate events from multiple devices through a centralized platform. In an SD-WAN deployment, this can help with troubleshooting connectivity issues, reviewing traffic behavior, and analyzing events across different branches. FortiManager has a different primary function: centralized device and configuration management. Using FortiManager and FortiAnalyzer together can provide both centralized configuration control and centralized operational visibility across a large Fortinet environment.

Question 129

Which metric specifically represents the delay experienced by packets on a monitored WAN path?

  1. Latency
  2. Jitter
  3. Packet loss
  4. Throughput

Correct Answer: 1

Explanation

Latency represents the delay experienced by packets while traveling across a network path. Lower latency is generally desirable for interactive and real-time applications because excessive delay can make communication feel slow or disconnected. FortiGate can measure latency through Performance SLA monitoring and compare the result against configured thresholds. If a WAN path develops excessive latency, SD-WAN can potentially select another eligible member according to the applicable rule. Latency is different from jitter because jitter measures variation in packet delay, while latency focuses on the actual delay experienced by traffic.

Question 130

Which feature can group multiple SD-WAN members into a logical interface or zone?

  1. Performance SLA
  2. SD-WAN zone
  3. Application Control
  4. FortiAnalyzer

Correct Answer: 2

Explanation

An SD-WAN zone provides a logical grouping for SD-WAN members. Members can represent physical WAN interfaces or supported logical and tunnel interfaces. Using a logical SD-WAN zone simplifies configuration because routing and security policies can reference the logical group instead of individually referencing every underlying member. FortiGate then uses SD-WAN rules and path-selection logic to determine which member should carry matching traffic. This design is particularly useful in environments with multiple WAN connections because administrators can manage the overall SD-WAN structure while still benefiting from individual member monitoring and steering.

Question 131

Which traffic characteristic is most important when identifying applications for application-aware SD-WAN steering?

  1. Application identity
  2. Interface cable length
  3. FortiGate serial number
  4. Administrator username

Correct Answer: 1

Explanation

Application identity allows FortiGate to recognize different applications and use that information when making traffic-steering decisions. This is valuable because applications can have different network requirements. Voice and video applications may require low latency, low jitter, and minimal packet loss, while software updates or backups may tolerate less favorable network conditions. Application-aware SD-WAN policies can therefore assign different strategies to different workloads. FortiGate can combine application identification with Performance SLA measurements to determine an appropriate WAN path. This provides more granular traffic control than simply applying one path-selection strategy to all network traffic.

Question 132

Which technology can dynamically create more direct branch-to-branch paths in an appropriate hub-and-spoke deployment?

  1. DHCP
  2. ADVPN
  3. DNS
  4. SNMP

Correct Answer: 2

Explanation

ADVPN can enable dynamic shortcut connectivity between branch locations in suitable hub-and-spoke deployments. Without direct shortcuts, traffic between branches may need to pass through a central hub, creating additional traffic flow and potentially increasing latency. ADVPN can allow suitable branch-to-branch communication to establish a more direct path when the required conditions are met. Fortinet deployments commonly combine ADVPN with IPsec and dynamic routing technologies. The exact behavior depends on the configured topology and supported features. ADVPN is therefore useful for improving scalability and reducing unnecessary traffic hairpinning in certain architectures.

Question 133

Which SD-WAN metric measures the percentage of packets that fail to reach their destination?

  1. Jitter
  2. Latency
  3. Packet loss
  4. Bandwidth

Correct Answer: 3

Explanation

Packet loss represents packets that fail to successfully reach their intended destination. High packet loss can occur because of congestion, unreliable WAN links, overloaded network equipment, or other transport problems. It can significantly affect applications because lost packets may require retransmission or can directly degrade real-time communication. FortiGate Performance SLA can monitor packet loss and compare it with configured thresholds. If a member exceeds the acceptable loss level, an SD-WAN rule may consider another eligible path. Monitoring packet loss is therefore an important part of maintaining reliable application connectivity across multiple WAN transports.

Question 134

Which FortiManager feature helps deploy consistent configurations to multiple FortiGate devices?

  1. Packet capture
  2. Configuration templates
  3. DNS filtering
  4. Traffic shaping

Correct Answer: 2

Explanation

FortiManager configuration templates help administrators deploy consistent settings across multiple managed FortiGate devices. This is particularly valuable in SD-WAN deployments where many branches require similar configurations for interfaces, VPNs, routing, security policies, and SD-WAN rules. Instead of manually configuring each device, administrators can use centralized templates and apply standardized settings. Device-specific values can be customized where required. This approach reduces repetitive work and helps minimize configuration inconsistencies. FortiManager also provides centralized management capabilities that are useful for maintaining large numbers of FortiGate devices.

Question 135

Which SD-WAN strategy is most closely associated with choosing paths according to quality measurements?

  1. Load Balance
  2. Manual
  3. Best Quality
  4. Lowest Cost

Correct Answer: 3

Explanation

Best Quality is designed to select a suitable path based on measured WAN performance. FortiGate can evaluate Performance SLA metrics such as latency, jitter, and packet loss when determining path quality. This makes the strategy useful for applications where network performance is more important than simply minimizing cost. If the preferred member becomes degraded, another member that satisfies the required conditions may become preferable. The final behavior depends on the configured SD-WAN rule, SLA requirements, and available members. Administrators should ensure that the selected SLA thresholds accurately represent the application’s needs.

Question 136

What is the primary purpose of the WAN underlay in an SD-WAN architecture?

  1. To provide the underlying network transport
  2. To store FortiAnalyzer logs
  3. To identify applications
  4. To authenticate administrators

Correct Answer: 1

Explanation

The WAN underlay provides the underlying network transport used by SD-WAN connectivity. Examples can include Internet broadband, MPLS, LTE, or other available WAN services. Above this transport, organizations may build logical overlays such as IPsec tunnels. SD-WAN can monitor different underlay paths and select suitable members according to configured rules and Performance SLA measurements. Separating underlay and overlay provides flexibility because different transport services can support the same logical network architecture. This allows organizations to combine multiple WAN technologies while maintaining centralized traffic-steering policies.

Question 137

Which SD-WAN strategy can use configured member costs while considering SLA requirements?

  1. Best Quality
  2. Load Balance
  3. Manual
  4. Lowest Cost (SLA)

Correct Answer: 4

Explanation

Lowest Cost (SLA) can use configured member costs while also considering whether paths satisfy required SLA conditions. This is useful when an organization operates WAN connections with different service costs. A lower-cost connection can be preferred when it provides acceptable performance, while a higher-cost connection can be used when the lower-cost option does not meet the required quality conditions. This approach allows administrators to balance operational cost and application performance. Correct member-cost values and appropriate SLA thresholds are important because they directly influence which paths remain eligible for traffic.

Question 138

Which topology normally uses one or more central hubs to connect branch sites?

  1. Full mesh
  2. Hub-and-spoke
  3. Peer-to-peer only
  4. Ring

Correct Answer: 2

Explanation

A hub-and-spoke topology connects branch or spoke sites through one or more central hubs. This architecture is common because it can simplify centralized security, routing, and management. In a traditional hub-and-spoke design, branch-to-branch traffic may pass through the hub, which can introduce additional traffic flow and latency. Fortinet technologies such as ADVPN can provide mechanisms for more direct branch-to-branch connectivity when appropriate. SD-WAN can operate within this architecture to select suitable paths based on application requirements, Performance SLA results, routing information, and available WAN members.

Question 139

Which feature allows administrators to match Internet services in SD-WAN policies without manually entering every destination IP address?

  1. Static route
  2. DNS server
  3. Internet Service Database
  4. DHCP relay

Correct Answer: 3

Explanation

The Internet Service Database provides predefined information about Internet services and their associated destinations. SD-WAN rules can use this information to identify traffic destined for recognized Internet services without requiring administrators to manually maintain every individual destination IP address. This can simplify policy creation, particularly for large or changing cloud and Internet services. Because service providers may use multiple addresses and change infrastructure over time, manually maintaining every address can become difficult. Using ISDB-based matching provides a more practical approach for applying specific SD-WAN steering policies to supported Internet services.

Question 140

What is the main advantage of combining application-aware SD-WAN rules with Performance SLA monitoring?

  1. It removes the need for routing
  2. It allows traffic to be steered according to application needs and path quality
  3. It disables IPsec encryption
  4. It forces every application onto the same WAN link

Correct Answer: 2

Explanation

Combining application-aware SD-WAN rules with Performance SLA monitoring allows FortiGate to consider both the type of traffic and the current quality of available WAN paths. Different applications can be assigned different requirements. For example, voice traffic may require low latency and jitter, while backup traffic may prioritize available bandwidth or cost. Performance SLA provides real-time path-quality information, while application-aware rules classify the traffic. Together, these features allow FortiGate to make more intelligent forwarding decisions and dynamically avoid WAN paths that no longer meet the requirements of specific applications.