View Full Fortinet NSE6_SDW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 141
Which SD-WAN feature allows traffic to be classified according to the application being used?
- Static Routing
- Application Identification
- DHCP Relay
- ARP Inspection
Correct Answer: 2
Explanation
Application identification allows FortiGate to recognize application traffic and use that information in SD-WAN policies. This is useful because different applications can have different network requirements. For example, voice and video traffic may require low latency and jitter, while backup traffic can often tolerate less favorable conditions. Once an application is identified, an SD-WAN rule can apply a specific steering strategy and Performance SLA requirements. This provides more granular control than simply routing all traffic according to destination. Application-aware steering is therefore an important capability for organizations that need different WAN treatment for different applications.
Question 142
Which SD-WAN metric indicates the amount of delay experienced by packets across a monitored path?
- Packet Loss
- Jitter
- Latency
- Throughput
Correct Answer: 3
Explanation
Latency measures the delay experienced by packets as they travel across a network path. In an SD-WAN environment, FortiGate can monitor latency through Performance SLA health checks and compare the measured value with configured thresholds. High latency can negatively affect interactive applications such as remote desktop, voice, video conferencing, and business applications. Latency is different from jitter because jitter measures variation in packet delay rather than the overall delay itself. By monitoring latency, FortiGate can identify WAN paths that are not meeting application requirements and potentially select another eligible SD-WAN member.
Question 143
What is the primary purpose of an SD-WAN Performance SLA?
- To monitor WAN path quality
- To create administrator accounts
- To configure antivirus signatures
- To assign switch VLANs
Correct Answer: 1
Explanation
Performance SLA is used to monitor the quality and availability of WAN paths. FortiGate can measure parameters such as latency, jitter, packet loss, and reachability against configured targets. These measurements allow SD-WAN to determine whether a member satisfies the conditions required by an SD-WAN rule. If a path becomes degraded, another eligible member may be selected depending on the configured strategy. Performance SLA therefore provides dynamic information about WAN health rather than relying only on whether an interface is physically up. Proper thresholds are important so that traffic is steered according to actual application requirements.
Question 144
Which SD-WAN strategy is designed to distribute traffic across multiple eligible members?
- Best Quality
- Lowest Cost
- Load Balance
- Manual
Correct Answer: 3
Explanation
Load Balance is designed to distribute traffic among multiple eligible SD-WAN members. This can help organizations use available WAN resources more efficiently instead of relying entirely on a single connection. The exact distribution depends on the SD-WAN configuration and traffic characteristics. Load balancing can be useful when multiple WAN links have sufficient quality and the organization wants to utilize their combined capacity. It differs from Best Quality, which focuses primarily on path performance, and Lowest Cost, which considers cost-related preferences. Administrators should select the strategy that matches their traffic patterns and operational requirements.
Question 145
Which technology is commonly used to create encrypted tunnels between FortiGate devices?
- IPsec VPN
- DHCP
- DNS
- SNMP
Correct Answer: 1
Explanation
IPsec VPN is commonly used to create secure encrypted tunnels between FortiGate devices. In SD-WAN deployments, IPsec tunnels can operate over different WAN transports and provide a secure overlay between sites. Multiple tunnels can be established to support redundancy and different connectivity options. SD-WAN can then monitor these tunnel paths and apply traffic-steering rules based on application requirements and Performance SLA results. The IPsec layer provides encryption and secure connectivity, while SD-WAN provides path-selection capabilities. Together, these technologies can create a flexible and secure multi-WAN architecture for branch connectivity.
Question 146
Which routing protocol is commonly used to dynamically exchange routes in larger SD-WAN environments?
- FTP
- SMTP
- BGP
- DHCP
Correct Answer: 3
Explanation
BGP can dynamically exchange routing information between FortiGate devices and other routing domains. In larger SD-WAN environments, dynamic routing can reduce the need for manually configured static routes. BGP can advertise reachable networks and react to topology changes, making it useful for scalable deployments. It can operate across suitable VPN overlays and integrate with SD-WAN architectures. Administrators can also use routing policies to control which routes are advertised or accepted. The exact BGP design depends on the network topology, addressing scheme, hub-and-spoke structure, and overall routing requirements.
Question 147
Which SD-WAN metric measures variation in packet delivery timing?
- Latency
- Packet Loss
- Jitter
- Bandwidth
Correct Answer: 3
Explanation
Jitter measures variation in packet delivery timing. A network path may have acceptable average latency but still experience significant jitter if packet delays vary considerably. This can negatively affect real-time applications such as voice and video because these applications depend on relatively consistent packet arrival. FortiGate can measure jitter through Performance SLA monitoring and compare it against configured thresholds. If jitter becomes excessive, an SD-WAN rule can potentially select another suitable member. Monitoring jitter separately from latency provides a more complete view of WAN quality for applications that are sensitive to timing variations.
Question 148
Which Fortinet platform is primarily designed for centralized FortiGate configuration and device management?
- FortiAnalyzer
- FortiManager
- FortiMail
- FortiAuthenticator
Correct Answer: 2
Explanation
FortiManager provides centralized management and configuration capabilities for FortiGate devices. It can organize managed devices and help administrators distribute policies and configuration changes from a central location. This is especially useful for SD-WAN deployments containing many branch FortiGates because common configurations can be standardized and deployed more efficiently. FortiManager can also help administrators manage configuration consistency across multiple sites. FortiAnalyzer has a different primary purpose, focusing on log collection, analysis, and reporting. Understanding the difference between these platforms is important when designing centralized Fortinet management and monitoring.
Question 149
What does packet loss indicate on an SD-WAN monitored path?
- Variation in delay
- Packets that were not successfully delivered
- Available bandwidth
- Application priority
Correct Answer: 2
Explanation
Packet loss indicates that some packets transmitted across the network path did not successfully reach their intended destination. Packet loss can occur because of congestion, unreliable connections, overloaded equipment, or other network problems. High packet loss can significantly affect applications, especially voice, video, and interactive services. FortiGate Performance SLA can monitor packet loss and compare the measured value against configured thresholds. If the loss level becomes unacceptable, an SD-WAN rule can potentially steer traffic toward another eligible member. This helps maintain application reliability when WAN conditions change.
Question 150
Which topology uses central hub devices to connect multiple branch or spoke locations?
- Full Mesh
- Ring
- Hub-and-Spoke
- Point-to-Point
Correct Answer: 3
Explanation
A hub-and-spoke topology uses central hub locations to connect multiple branch or spoke sites. This architecture can simplify centralized routing, security inspection, and network management. Traditionally, branch-to-branch communication may pass through the hub, which can create additional traffic flow and latency. Fortinet technologies such as ADVPN can provide more direct branch connectivity in suitable deployments. SD-WAN can operate within this architecture and select appropriate paths according to configured rules and Performance SLA measurements. Hub-and-spoke designs are commonly used when centralized control and scalable branch connectivity are important considerations.
Question 151
Which feature can identify predefined Internet services for use in SD-WAN traffic matching?
- Internet Service Database
- DHCP Server
- DNS Forwarder
- ARP Table
Correct Answer: 1
Explanation
The Internet Service Database provides predefined information about supported Internet services and their associated destinations. SD-WAN rules can use this information to match traffic without requiring administrators to manually enter every destination IP address. This can simplify policies for cloud applications and other Internet-based services that may use multiple or changing addresses. Using ISDB-based matching can reduce administrative effort and make SD-WAN policies easier to maintain. Administrators can then associate specific Internet services with appropriate path-selection strategies and Performance SLA requirements based on the organization’s traffic and application needs.
Question 152
What is a major benefit of using multiple WAN connections with SD-WAN?
- It removes all firewall policies
- It guarantees equal latency on every link
- It provides additional path and failover options
- It eliminates the need for routing
Correct Answer: 3
Explanation
Multiple WAN connections provide additional path choices and improve resilience when used with SD-WAN. FortiGate can monitor the available connections and apply configured steering policies to determine which path should carry specific traffic. If a connection becomes unavailable or fails its required SLA conditions, another eligible member can potentially carry the traffic. Multiple WAN links can also provide additional capacity and allow organizations to combine different transport technologies. However, simply having multiple links does not guarantee effective failover. Proper SD-WAN rules, routing, health checks, and security policies are required.
Question 153
Which FortiManager feature is useful for applying standardized SD-WAN configurations to multiple branches?
- Configuration Templates
- Packet Capture
- DNS Filter
- Antivirus Scanner
Correct Answer: 1
Explanation
Configuration templates in FortiManager can help administrators standardize and distribute configurations across multiple FortiGate devices. In an SD-WAN deployment, many branch offices may require similar settings for WAN interfaces, VPNs, routing, SD-WAN rules, and security policies. Templates reduce the amount of repetitive manual configuration and help maintain consistency. Device-specific parameters can still be customized when required. This approach becomes increasingly valuable as the number of branches grows. Centralized templates also make it easier to apply planned configuration changes systematically rather than configuring every FortiGate individually.
Question 154
Which SD-WAN strategy focuses on selecting a path according to measured network quality?
- Manual
- Best Quality
- Load Balance
- Lowest Cost
Correct Answer: 2
Explanation
Best Quality focuses on selecting an appropriate path according to measured network performance. FortiGate can use Performance SLA information such as latency, jitter, and packet loss when evaluating available members. This makes the strategy useful for applications where service quality is more important than simply minimizing cost. If the preferred path becomes degraded, another eligible member may be selected according to the rule and SLA conditions. Administrators should configure suitable thresholds because overly strict values may exclude usable paths, while overly relaxed values may allow degraded WAN links to continue carrying sensitive traffic.
Question 155
What is the primary purpose of the SD-WAN underlay?
- To provide the underlying WAN transport
- To store firewall logs
- To identify applications
- To manage administrators
Correct Answer: 1
Explanation
The underlay represents the underlying network transport used by an SD-WAN deployment. It can include Internet broadband, MPLS, LTE, or other WAN services. Logical overlays such as IPsec tunnels can operate over these transports and provide secure connectivity between sites. SD-WAN monitors available paths and applies traffic-steering policies to select appropriate members. Separating the underlay from the overlay allows organizations to use multiple transport technologies while maintaining a consistent logical network architecture. This design provides flexibility and allows WAN services to be changed or combined without necessarily redesigning the complete overlay network.
Question 156
Which Fortinet product is primarily responsible for centralized log analysis and reporting?
- FortiManager
- FortiGate
- FortiAnalyzer
- FortiSwitch
Correct Answer: 3
Explanation
FortiAnalyzer is primarily used for centralized log collection, analysis, reporting, and monitoring. FortiGate devices can send logs to FortiAnalyzer so administrators can investigate events from multiple locations through a central platform. In SD-WAN environments, these logs can assist with troubleshooting connectivity problems, reviewing traffic behavior, and analyzing events across branch devices. FortiManager serves a different primary purpose by providing centralized device and configuration management. Organizations can use both platforms together to achieve centralized administration and operational visibility across a large Fortinet deployment.
Question 157
Which SD-WAN option is most appropriate when an administrator wants to prefer a lower-cost path while still requiring acceptable SLA performance?
- Best Quality
- Lowest Cost (SLA)
- Load Balance
- Manual
Correct Answer: 2
Explanation
Lowest Cost (SLA) is designed for scenarios where administrators want to consider member cost while still requiring paths to satisfy defined SLA conditions. This can be useful when an organization has WAN services with different operational costs. A lower-cost connection can be preferred as long as it provides acceptable latency, jitter, packet loss, or availability according to the configured requirements. If the lower-cost member fails the required SLA, another eligible path may be selected. This approach helps balance WAN expenses with application performance and service-quality requirements.
Question 158
Which FortiGate feature can use source and destination information to match traffic for SD-WAN steering?
- SD-WAN Rules
- FortiAnalyzer Reports
- DHCP Relay
- Antivirus Profiles
Correct Answer: 1
Explanation
SD-WAN rules can use traffic characteristics such as source and destination information when determining which policy should handle traffic. This allows administrators to create different steering behavior for different networks, servers, applications, or services. For example, traffic destined for a corporate data center can use a preferred WAN path while general Internet traffic uses another strategy. Additional matching criteria may include applications, services, and Internet Service Database information. Combining traffic matching with Performance SLA measurements allows FortiGate to make path-selection decisions based on both traffic identity and WAN conditions.
Question 159
What can FortiGate do when an SD-WAN member fails the Performance SLA required by a rule?
- It can select another eligible member
- It permanently deletes the member
- It disables every firewall policy
- It removes all routing information
Correct Answer: 1
Explanation
When an SD-WAN member fails the Performance SLA requirements associated with a rule, FortiGate can consider another eligible member for the affected traffic. SLA failure can result from excessive latency, jitter, packet loss, or loss of reachability depending on the configured health check. This behavior provides dynamic traffic steering and helps prevent applications from continuing to use a degraded path when suitable alternatives exist. The actual outcome depends on the SD-WAN strategy, rule configuration, SLA thresholds, and availability of other members. It does not automatically mean the physical interface is permanently disabled.
Question 160
Which statement best describes the role of an SD-WAN rule?
- It stores FortiAnalyzer reports
- It defines how matching traffic should be steered across SD-WAN members
- It assigns IP addresses to users
- It replaces all security policies
Correct Answer: 2
Explanation
An SD-WAN rule defines how matching traffic should be steered across available SD-WAN members. Administrators can use different matching criteria and select an appropriate path-selection strategy for each traffic class. Performance SLA results can influence whether a member is considered suitable for the rule. This allows different applications, destinations, or services to receive different WAN treatment. SD-WAN rules do not replace firewall policies or DHCP services; instead, they work within the broader FortiGate routing and security architecture. Proper rule design is essential for achieving predictable traffic steering and WAN resilience.