{"id":17086,"date":"2026-09-21T06:23:53","date_gmt":"2026-09-21T06:23:53","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17086"},"modified":"2026-09-21T06:23:53","modified_gmt":"2026-09-21T06:23:53","slug":"fortinet-nse6_sdw_ad-7-6-practice-test-questions-and-exam-dumps-part12-q221-240","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse6_sdw_ad-7-6-practice-test-questions-and-exam-dumps-part12-q221-240\/","title":{"rendered":"Fortinet NSE6_SDW_AD-7.6 Practice Test Questions and Exam Dumps Part12 Q221-240"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse6-sdw-ad-7-6-exam-dumps\"><b>Fortinet NSE6_SDW_AD-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 221<\/b><\/h3>\n<p><b>Which SD-WAN setting determines the order or preference in which available members are considered for traffic forwarding?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SD-WAN strategy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP scope<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log filter<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The SD-WAN strategy determines how FortiGate evaluates eligible members when forwarding traffic that matches an SD-WAN rule. Depending on the selected strategy, FortiGate may prioritize the best-quality path, lowest-cost path, load distribution, or manually preferred members. The strategy works together with other rule criteria and Performance SLA information. It does not simply represent the physical interface configuration. Administrators should select a strategy based on application requirements and business priorities. Correctly configuring the strategy allows WAN traffic to be directed according to the intended operational behavior while maintaining flexibility when network conditions change.<\/span><\/p>\n<h3><b>Question 222<\/b><\/h3>\n<p><b>An administrator wants to prevent a WAN link with excessive packet loss from carrying business-critical traffic. Which feature should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP relay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static ARP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Performance SLA can be configured to monitor packet loss and determine whether a WAN member satisfies the quality requirements for particular traffic. The administrator can define an acceptable packet-loss threshold within the health-check configuration. When the measured loss exceeds that threshold, the member can become unsuitable for an SD-WAN rule that depends on the SLA. Another eligible member may then be selected. This provides dynamic path selection based on actual network conditions rather than relying only on whether the physical interface is operational. It is especially useful for protecting latency-sensitive or business-critical applications from degraded WAN paths.<\/span><\/p>\n<h3><b>Question 223<\/b><\/h3>\n<p><b>Which SD-WAN component groups multiple interfaces so they can be referenced as a logical WAN service?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SD-WAN zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS zone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VDOM link<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An SD-WAN zone can logically group SD-WAN members so that policies and routing configurations can reference the group rather than individual physical interfaces. This simplifies configuration when multiple WAN links provide the same logical service. Instead of creating separate references throughout the configuration, an administrator can use the appropriate SD-WAN zone. The actual member selection is still influenced by SD-WAN rules, strategies, and Performance SLA conditions. Logical grouping becomes especially useful in larger deployments where several transport links must be managed consistently while retaining individual member health and path-selection behavior.<\/span><\/p>\n<h3><b>Question 224<\/b><\/h3>\n<p><b>Which protocol is commonly used to exchange routing information dynamically between SD-WAN sites?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BGP is commonly used for dynamic routing between SD-WAN sites, especially in larger deployments where many prefixes must be exchanged. Instead of manually configuring every route, FortiGate devices can use BGP to advertise and learn network prefixes dynamically. BGP can operate over suitable IPsec overlay connections and can be combined with SD-WAN path selection. Administrators can also apply routing policies to control which prefixes are advertised or preferred. The exact design depends on the topology and routing requirements. Proper route filtering is important to prevent unwanted route propagation across the SD-WAN environment.<\/span><\/p>\n<h3><b>Question 225<\/b><\/h3>\n<p><b>What is the main purpose of an SD-WAN health check target?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide a destination against which path quality can be measured<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To assign IP addresses to clients<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To authenticate administrators<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To store firewall logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A health-check target provides a destination that FortiGate can use to evaluate WAN path reachability and quality. Depending on the configured probe type, FortiGate can measure characteristics such as latency, jitter, packet loss, or availability. Choosing an appropriate target is important because the target should represent the service or destination whose connectivity matters to the organization. The results are used by Performance SLA and can influence SD-WAN member eligibility. A poorly selected target may produce misleading results, so administrators should choose reliable and reachable endpoints that accurately represent the desired network service.<\/span><\/p>\n<h3><b>Question 226<\/b><\/h3>\n<p><b>Which SD-WAN strategy is most appropriate when an administrator wants to explicitly define the preferred member order?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Best Quality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load Balance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lowest Cost<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Manual strategy allows administrators to explicitly define the preferred order of SD-WAN members for matching traffic. This can be useful when a specific WAN link should normally carry traffic and another link should act as a backup. Unlike Best Quality, the selection is not primarily based on continuously measured path-quality ranking. Manual behavior provides predictable preference when the network design requires a fixed order. Performance SLA can still be relevant when determining whether members meet required conditions, depending on the configuration. Administrators should use manual preference carefully when WAN performance varies frequently.<\/span><\/p>\n<h3><b>Question 227<\/b><\/h3>\n<p><b>Which SD-WAN metric is most directly associated with the consistency of packet arrival timing?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Throughput<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Jitter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet loss<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Latency<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Jitter measures variation in packet arrival or transmission delay and is therefore associated with consistency of packet timing. A path with high jitter may deliver packets at significantly different intervals, which can negatively affect voice, video, and other real-time applications. FortiGate can measure jitter through Performance SLA health checks and use the result when evaluating SD-WAN members. Jitter is different from average latency, which represents overall delay. A path can have relatively low average latency while still experiencing high jitter. Monitoring both values provides a more accurate understanding of WAN suitability for real-time traffic.<\/span><\/p>\n<h3><b>Question 228<\/b><\/h3>\n<p><b>Which Fortinet solution can provide centralized visibility into SD-WAN events and historical logs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiManager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAuthenticator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiMail<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer provides centralized log collection, analysis, reporting, and historical visibility for Fortinet devices. In an SD-WAN deployment, administrators can use centralized logs to investigate path changes, traffic behavior, connectivity events, and other operational information. This is different from FortiManager, whose primary purpose is centralized management and configuration of FortiGate devices. FortiAnalyzer can help identify patterns over time that may not be obvious from real-time monitoring alone. Centralized logging is particularly valuable when troubleshooting multiple branches because administrators can investigate events from different devices through a consolidated platform.<\/span><\/p>\n<h3><b>Question 229<\/b><\/h3>\n<p><b>A WAN link has low latency but very high packet loss. What should an administrator understand about this path?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It is automatically the best path<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet loss may make it unsuitable for an SLA-controlled rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Low latency guarantees application quality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The link must always be selected first<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Low latency alone does not guarantee that a WAN path is suitable for an application. High packet loss can seriously affect application performance, particularly for voice, video, and reliable data transfers. If an SD-WAN rule uses Performance SLA and has a packet-loss threshold, the affected member may fail the SLA even though its latency is excellent. FortiGate can then select another eligible member according to the configured strategy. This illustrates why multiple performance metrics should be considered rather than relying on a single measurement. WAN quality is generally evaluated using the combination of relevant SLA conditions.<\/span><\/p>\n<h3><b>Question 230<\/b><\/h3>\n<p><b>Which technology provides encrypted tunnel connectivity that can serve as an SD-WAN overlay?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ICMP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IPsec provides encrypted tunnel connectivity and is commonly used to create SD-WAN overlay paths between FortiGate devices. The underlying WAN services can include Internet, MPLS, LTE, or other transports. The IPsec tunnel provides logical and secure connectivity over those transports. SD-WAN can then evaluate these paths and steer traffic according to rules and Performance SLA results. Using encrypted overlays allows organizations to maintain secure communication between branches while using multiple WAN services. Administrators must correctly configure tunnel endpoints, routing, authentication, and security settings to ensure reliable overlay connectivity.<\/span><\/p>\n<h3><b>Question 231<\/b><\/h3>\n<p><b>Which feature allows SD-WAN traffic steering based on recognized applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application-aware SD-WAN rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS cache<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application-aware SD-WAN rules allow administrators to apply different steering behavior based on identified applications. This enables organizations to treat traffic according to business importance rather than only using source and destination addresses. For example, collaboration applications can be assigned stricter performance requirements while less-sensitive traffic can use another WAN path. Application identification must be available to the FortiGate so that traffic can match the appropriate rule. Performance SLA can then provide path-quality information for selecting an eligible member. This combination creates policy-driven WAN steering that can adapt to changing link conditions.<\/span><\/p>\n<h3><b>Question 232<\/b><\/h3>\n<p><b>What is the primary purpose of the SD-WAN underlay?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide the physical or transport connectivity used by the overlay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To store application signatures<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To collect security logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To manage administrator accounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The underlay consists of the underlying WAN transports that provide connectivity for the network. Examples can include Internet circuits, MPLS connections, broadband, and cellular services. The overlay can use these transports to establish logical connectivity, such as IPsec tunnels between FortiGate devices. SD-WAN evaluates available paths across these transports and can steer traffic according to configured policies and performance conditions. Understanding the distinction between underlay and overlay is important when troubleshooting. An overlay tunnel may be affected by problems in the physical or logical underlay even though the tunnel configuration itself has not changed.<\/span><\/p>\n<h3><b>Question 233<\/b><\/h3>\n<p><b>Which SD-WAN strategy can select a member according to measured quality rather than simply using a fixed preference?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Best Quality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static Route<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Best Quality uses measured WAN performance to select an appropriate SD-WAN member. Performance SLA information can include latency, jitter, packet loss, and reachability depending on the health-check configuration. This makes the strategy useful when WAN conditions change and the preferred path should reflect current network quality. A fixed manual preference does not provide the same quality-based selection behavior. Administrators should configure meaningful SLA thresholds so that FortiGate can distinguish acceptable and degraded paths. Best Quality is particularly useful for applications where consistent network performance is more important than selecting a path solely because of cost or static preference.<\/span><\/p>\n<h3><b>Question 234<\/b><\/h3>\n<p><b>What happens when a Performance SLA target becomes unreachable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The corresponding path can fail the SLA evaluation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">All FortiGate interfaces shut down<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The FortiGate configuration is erased<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Every SD-WAN rule is deleted<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">If a Performance SLA target becomes unreachable, the associated health check can fail its reachability test. Depending on the configuration, the monitored member may then become ineligible for SD-WAN traffic governed by that SLA. FortiGate can use another eligible member if the applicable SD-WAN strategy allows it. This provides a mechanism for detecting connectivity problems that may not be visible simply by checking whether a physical interface is up. Administrators should select reliable SLA targets and configure suitable failure and recovery behavior so that temporary problems do not cause unnecessary or unstable path changes.<\/span><\/p>\n<h3><b>Question 235<\/b><\/h3>\n<p><b>Which FortiManager capability is particularly useful for maintaining consistent SD-WAN configurations across many branches?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration templates<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet capture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Antivirus scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration templates in FortiManager help administrators maintain consistent configurations across multiple FortiGate branches. An organization can define common SD-WAN settings and apply them to devices that share similar requirements. This can include interface settings, VPN configurations, routing, policies, and SD-WAN rules. Templates reduce repetitive configuration work and help minimize inconsistencies between branches. Device-specific values can be handled separately when required. Centralized configuration is particularly useful in large deployments because changes can be planned and applied systematically instead of logging into every FortiGate individually.<\/span><\/p>\n<h3><b>Question 236<\/b><\/h3>\n<p><b>Which metric would indicate that packets are being discarded before reaching the destination?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Jitter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Latency<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet loss<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Throughput<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Packet loss indicates that packets are not successfully reaching the intended destination or are otherwise lost during transmission. High packet loss can significantly affect network applications because missing packets may require retransmission or cause degraded real-time communication. Performance SLA can monitor packet loss and compare it with configured thresholds. An SD-WAN rule can use these results to avoid members that no longer satisfy required quality conditions. Packet loss is different from latency, which measures delay, and jitter, which measures variation in delay. Monitoring packet loss is therefore important when evaluating overall WAN reliability and application performance.<\/span><\/p>\n<h3><b>Question 237<\/b><\/h3>\n<p><b>Which SD-WAN design can provide direct branch-to-branch connectivity without requiring all traffic to remain routed through the hub?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ADVPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">ADVPN can provide dynamic shortcut connectivity between branch locations in suitable hub-and-spoke deployments. Without shortcuts, branch-to-branch traffic may need to pass through a central hub, creating additional latency and consuming hub resources. ADVPN can dynamically establish a more direct path when traffic requirements and configuration permit it. This can improve efficiency for inter-branch communication. Fortinet deployments commonly combine ADVPN with IPsec and dynamic routing technologies. The actual behavior depends on the configured topology, routing, tunnel parameters, and supported features, so administrators should validate the complete design before deployment.<\/span><\/p>\n<h3><b>Question 238<\/b><\/h3>\n<p><b>Which SD-WAN rule criterion can be used to steer traffic originating from a particular network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Source address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">System time<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device serial number<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firmware checksum<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Source address can be used as a matching criterion in an SD-WAN rule to identify traffic originating from a particular network or host group. This allows administrators to apply different WAN behavior to different users, departments, branches, or internal subnets. For example, traffic from a business-critical subnet can be assigned a stricter Performance SLA requirement than general user traffic. Other rule criteria may include destination, application, service, or Internet Service Database information. Combining source-based matching with an appropriate SD-WAN strategy provides granular control over how traffic uses available WAN members.<\/span><\/p>\n<h3><b>Question 239<\/b><\/h3>\n<p><b>Which statement best describes an SD-WAN member?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A user account stored in FortiGate<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A WAN interface or logical path participating in SD-WAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A FortiAnalyzer report<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A firewall administrator profile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An SD-WAN member represents a WAN interface or logical path that participates in SD-WAN path selection. Depending on the design, members can represent different physical or logical WAN connections. FortiGate evaluates these members using SD-WAN rules, strategies, and Performance SLA information. Each member can have characteristics such as cost or priority that influence path selection. Understanding members is fundamental because SD-WAN rules ultimately determine how traffic is distributed among available paths. If a member becomes unavailable or fails the required SLA conditions, another eligible member can potentially be selected for matching traffic.<\/span><\/p>\n<h3><b>Question 240<\/b><\/h3>\n<p><b>Which combination is most useful for steering business-critical applications away from degraded WAN links?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP and DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application matching, SD-WAN rules, and Performance SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP and MAC address learning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP and SNMP only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application matching, SD-WAN rules, and Performance SLA can work together to steer business-critical traffic according to current WAN conditions. Application matching identifies the relevant traffic, while the SD-WAN rule defines how that traffic should be handled. Performance SLA evaluates whether available WAN members meet required quality conditions such as latency, jitter, packet loss, or reachability. If the preferred path becomes degraded, another eligible member can be selected according to the configured strategy. This combination provides more intelligent traffic steering than relying only on static routing or physical interface availability.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE6_SDW_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 221 Which SD-WAN setting determines the order or preference in which available members are considered for traffic forwarding? SD-WAN strategy DNS server DHCP scope Log filter Correct Answer: 1 Explanation The SD-WAN strategy determines how FortiGate evaluates eligible members when forwarding traffic that [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17086"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17086"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17086\/revisions"}],"predecessor-version":[{"id":17087,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17086\/revisions\/17087"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17086"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17086"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17086"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}