{"id":17090,"date":"2026-09-21T06:24:33","date_gmt":"2026-09-21T06:24:33","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17090"},"modified":"2026-09-21T06:24:33","modified_gmt":"2026-09-21T06:24:33","slug":"fortinet-nse6_sdw_ad-7-6-practice-test-questions-and-exam-dumps-part14-q261-280","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse6_sdw_ad-7-6-practice-test-questions-and-exam-dumps-part14-q261-280\/","title":{"rendered":"Fortinet NSE6_SDW_AD-7.6 Practice Test Questions and Exam Dumps Part14 Q261-280"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse6-sdw-ad-7-6-exam-dumps\"><b>Fortinet NSE6_SDW_AD-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 261<\/b><\/h3>\n<p><b>Which SD-WAN component determines whether a monitored WAN path meets configured quality thresholds?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP Server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Performance SLA evaluates the quality and availability of monitored SD-WAN paths against configured thresholds. Depending on the health-check configuration, FortiGate can measure latency, jitter, packet loss, and reachability. These measurements help determine whether an SD-WAN member is suitable for traffic associated with a particular rule. If a path fails the required conditions, another eligible member may be selected according to the configured strategy. Performance SLA therefore provides an important foundation for dynamic SD-WAN path selection. Administrators should configure thresholds according to actual application requirements rather than choosing unnecessarily strict or overly permissive values.<\/span><\/p>\n<h3><b>Question 262<\/b><\/h3>\n<p><b>Which SD-WAN strategy is designed to distribute traffic among multiple eligible members?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Best Quality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load Balance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lowest Cost<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Load Balance is designed to distribute traffic among multiple eligible SD-WAN members. This can improve utilization when an organization has several WAN connections that are suitable for the same type of traffic. Rather than depending entirely on one preferred link, the strategy allows available paths to participate in forwarding. Eligibility can still depend on configured Performance SLA conditions. Load Balance differs from Best Quality, which focuses on measured path quality, and Manual, which provides an explicit preference order. The appropriate strategy depends on bandwidth availability, application requirements, WAN costs, and the desired traffic-distribution behavior.<\/span><\/p>\n<h3><b>Question 263<\/b><\/h3>\n<p><b>Which metric specifically indicates variation in packet delivery delay?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Latency<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet Loss<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Jitter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Throughput<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Jitter indicates variation in packet delivery delay. Unlike latency, which represents packet delay, jitter describes how consistently that delay occurs from packet to packet. High jitter can be especially problematic for voice and video because these applications depend on consistent packet timing. FortiGate can monitor jitter through Performance SLA health checks and use the result when evaluating SD-WAN members. Administrators can configure thresholds based on application requirements. A WAN path with acceptable latency can still be unsuitable for real-time traffic if its jitter is excessive, which is why multiple SLA metrics should be considered together.<\/span><\/p>\n<h3><b>Question 264<\/b><\/h3>\n<p><b>Which Fortinet product provides centralized management of FortiGate configurations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiManager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiMail<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiWeb<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiManager provides centralized management and configuration capabilities for FortiGate devices. In an SD-WAN environment, it can help administrators manage configurations across many branches from a centralized platform. This can include device settings, policies, routing configurations, and SD-WAN-related configurations. FortiManager helps reduce repetitive administrative work and promotes consistency across managed devices. FortiAnalyzer serves a different primary purpose, focusing on centralized logging, analysis, and reporting. Using both solutions together can provide centralized configuration control through FortiManager and centralized visibility into operational events through FortiAnalyzer.<\/span><\/p>\n<h3><b>Question 265<\/b><\/h3>\n<p><b>What happens when packet loss on an SD-WAN member exceeds the configured SLA threshold?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The member may become ineligible for the affected rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">All FortiGate interfaces shut down<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The firewall configuration is erased<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">All VPN tunnels are permanently deleted<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When packet loss exceeds the configured Performance SLA threshold, the monitored member may become ineligible for traffic governed by that SLA. FortiGate can then evaluate other available members and select an eligible path according to the configured SD-WAN strategy. This behavior helps prevent important traffic from continuing to use a degraded WAN path. The physical interface itself does not necessarily shut down. Instead, its suitability for the particular SD-WAN rule is affected. Correct threshold configuration is important because thresholds that are too strict can cause unnecessary path changes, while thresholds that are too relaxed may allow poor-quality links to remain in use.<\/span><\/p>\n<h3><b>Question 266<\/b><\/h3>\n<p><b>Which SD-WAN component represents an individual WAN path participating in path selection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SD-WAN member<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer report<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall address group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An SD-WAN member represents an individual WAN interface or logical path that participates in SD-WAN forwarding decisions. Examples can include Internet, MPLS, LTE, or other WAN connections. FortiGate evaluates members according to SD-WAN rules, configured strategies, and Performance SLA results. Members can also have characteristics such as cost or priority that influence selection. If a member becomes unavailable or fails required SLA conditions, another eligible member can potentially be selected. Understanding the role of members is essential because SD-WAN ultimately uses these paths to forward traffic according to configured policy.<\/span><\/p>\n<h3><b>Question 267<\/b><\/h3>\n<p><b>Which protocol can dynamically exchange routing information across an SD-WAN overlay?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BGP can dynamically exchange routing information between FortiGate devices or other routing peers across an SD-WAN environment. This is especially useful when a deployment contains many sites and manually maintaining routes would become difficult. BGP can operate over suitable IPsec overlay connections and can advertise reachable networks between locations. Administrators can apply routing policies to control route advertisements and selection. SD-WAN and BGP solve different but complementary problems: BGP can determine which networks are reachable, while SD-WAN can determine which available path should carry matching traffic based on configured rules and performance conditions.<\/span><\/p>\n<h3><b>Question 268<\/b><\/h3>\n<p><b>Which feature allows FortiGate to identify traffic destined for supported cloud or Internet services using predefined service information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet Service Database<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static ARP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP Relay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Forwarder<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Internet Service Database provides predefined information about supported Internet and cloud services. SD-WAN rules can use ISDB entries to identify traffic destined for recognized services without requiring administrators to manually maintain every destination IP address. This is useful because large Internet services may use many addresses and their infrastructure can change over time. By using ISDB information, administrators can create application or service-specific SD-WAN rules more efficiently. These rules can then apply an appropriate strategy and Performance SLA requirements to determine how the traffic should use available WAN members.<\/span><\/p>\n<h3><b>Question 269<\/b><\/h3>\n<p><b>Which SD-WAN strategy emphasizes selecting a path based on measured network quality?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load Balance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Best Quality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lowest Cost<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Best Quality emphasizes selecting an appropriate SD-WAN member based on measured network performance. Performance SLA can provide information such as latency, jitter, packet loss, and reachability. FortiGate can use these measurements to determine which eligible path provides the required quality. This strategy is useful for applications where network performance is more important than minimizing WAN cost. It is different from Manual, where the administrator specifies a preferred order, and Lowest Cost, where cost is an important selection factor. Realistic SLA thresholds are important to ensure that quality-based decisions reflect actual application needs.<\/span><\/p>\n<h3><b>Question 270<\/b><\/h3>\n<p><b>Which topology normally connects branch locations through centralized hub devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full Mesh<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hub-and-Spoke<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Broadcast<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hub-and-spoke topology connects multiple branch or spoke sites through centralized hub devices. This design can simplify centralized routing, security inspection, and network management. One limitation is that traffic between two branches may need to pass through the hub, potentially increasing latency and consuming hub resources. Fortinet ADVPN can provide dynamic shortcut connectivity between suitable spoke sites, reducing unnecessary traffic hairpinning. SD-WAN can also operate within hub-and-spoke designs and select appropriate WAN paths based on application requirements, Performance SLA conditions, and configured steering strategies.<\/span><\/p>\n<h3><b>Question 271<\/b><\/h3>\n<p><b>Which metric is directly associated with the delay experienced by packets across a WAN path?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Latency<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Jitter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet Loss<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Throughput<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Latency represents the delay experienced by packets while traveling between endpoints across a network path. It is an important Performance SLA metric because excessive delay can negatively affect interactive applications such as voice, video conferencing, remote desktop, and transactional systems. FortiGate can monitor latency and compare it against configured thresholds. If a member exceeds the required threshold, it may become unsuitable for an SD-WAN rule that depends on that SLA. Latency should be evaluated together with jitter and packet loss because a low-latency path can still provide poor application performance when other quality metrics are degraded.<\/span><\/p>\n<h3><b>Question 272<\/b><\/h3>\n<p><b>Which Fortinet product is primarily used for centralized collection and analysis of FortiGate logs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiManager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiGate<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiAnalyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FortiSwitch<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiAnalyzer is primarily used for centralized log collection, analysis, reporting, and monitoring. In an SD-WAN deployment, multiple FortiGate devices can send logs to FortiAnalyzer, allowing administrators to investigate events from different branches through a centralized platform. This can help with troubleshooting WAN behavior, security events, connectivity problems, and traffic patterns. FortiManager has a different primary function focused on device and configuration management. Combining both products can provide centralized configuration through FortiManager and centralized operational visibility through FortiAnalyzer, which is useful in large distributed Fortinet deployments.<\/span><\/p>\n<h3><b>Question 273<\/b><\/h3>\n<p><b>Which SD-WAN strategy allows an administrator to define a specific member preference order?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Best Quality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lowest Cost<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load Balance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Manual strategy allows an administrator to explicitly define the preferred order of SD-WAN members. This is useful when an organization wants a particular WAN link to be preferred and another link to act as a backup. Unlike Best Quality, Manual selection is based on administrator-defined preference rather than primarily ranking paths by measured quality. Performance SLA conditions can still influence member eligibility depending on the configuration. Manual preference is useful when predictable path selection is required, but administrators should understand that fixed preferences may not always reflect changing WAN conditions.<\/span><\/p>\n<h3><b>Question 274<\/b><\/h3>\n<p><b>Which technology provides encrypted connectivity for an SD-WAN overlay across an untrusted WAN transport?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IPsec VPN provides encrypted connectivity and is commonly used to build secure SD-WAN overlay paths across untrusted WAN transports such as the public Internet. The underlying transport provides connectivity, while IPsec protects the logical communication between FortiGate endpoints. Multiple IPsec tunnels can be used to provide redundancy and additional path choices. SD-WAN can then monitor and steer traffic across these paths according to configured rules and Performance SLA results. This combination allows organizations to use cost-effective WAN services while maintaining encrypted connectivity between branches, data centers, and other network locations.<\/span><\/p>\n<h3><b>Question 275<\/b><\/h3>\n<p><b>Which Performance SLA metric would be most concerning for an application that requires consistent packet timing?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Jitter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface description<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MAC address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrative distance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Jitter is particularly important for applications that require consistent packet timing, such as voice and video. High jitter means that packet delivery intervals vary significantly, which can cause interruptions or quality degradation in real-time communication. FortiGate can monitor jitter through Performance SLA and compare the result against configured thresholds. If a member exceeds the acceptable threshold, SD-WAN can potentially select another eligible path for the affected traffic. Latency and packet loss also matter, but jitter specifically addresses variation in packet timing, making it an important metric for real-time application traffic.<\/span><\/p>\n<h3><b>Question 276<\/b><\/h3>\n<p><b>Which SD-WAN feature allows traffic to be matched based on an application&#8217;s identity rather than only its IP address?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application-aware SD-WAN rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP snooping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application-aware SD-WAN rules allow FortiGate to identify and steer traffic based on application identity. This provides more granular control than simply matching IP addresses because different applications can receive different WAN treatment even when they use shared infrastructure. Administrators can combine application matching with Performance SLA requirements and SD-WAN strategies. For example, business-critical applications can be assigned strict quality requirements while general traffic uses a different path-selection policy. Application-aware steering is particularly useful in modern environments where cloud applications and services may use changing destination addresses.<\/span><\/p>\n<h3><b>Question 277<\/b><\/h3>\n<p><b>Which component separates the physical WAN connections from the logical secure tunnels used between sites?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Underlay and Overlay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control and DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP and NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy and Profile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The underlay represents the physical or transport WAN connections, while the overlay represents logical connectivity built across those transports. The underlay may include Internet, MPLS, LTE, or broadband services. The overlay can use IPsec tunnels to provide secure communication between FortiGate devices. SD-WAN operates across these paths and can steer traffic based on configured policies and Performance SLA measurements. This separation allows organizations to change or combine WAN transports without completely redesigning their logical network. It also helps troubleshooting by distinguishing transport problems from overlay tunnel or routing problems.<\/span><\/p>\n<h3><b>Question 278<\/b><\/h3>\n<p><b>Which SD-WAN rule criterion can identify traffic intended for a specific application category?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical temperature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device serial number<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Administrator name<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Application criterion allows an SD-WAN rule to identify traffic according to application information. This makes it possible to apply different steering behavior to different applications. For example, voice or business-critical applications can be associated with strict Performance SLA requirements, while less-sensitive traffic can use another strategy. Application-based rules can also be combined with source, destination, service, or ISDB criteria. Proper application identification is important because FortiGate needs to recognize the traffic before the corresponding rule can be matched. This provides granular control over WAN usage based on business and application requirements.<\/span><\/p>\n<h3><b>Question 279<\/b><\/h3>\n<p><b>What is a key benefit of using multiple WAN transports in an SD-WAN deployment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Greater path diversity and resilience<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Elimination of all routing protocols<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatic removal of security policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Guaranteed unlimited bandwidth<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Using multiple WAN transports provides greater path diversity and resilience. An organization may combine Internet, MPLS, LTE, or other connectivity types so that traffic has alternative paths when one service becomes unavailable or degraded. SD-WAN can evaluate these paths using Performance SLA and select appropriate members according to configured rules and strategies. Multiple transports can also help distribute traffic and optimize WAN utilization. However, using multiple links does not automatically guarantee unlimited bandwidth or perfect application performance. Proper configuration, monitoring, routing, and security policies are still required to achieve reliable SD-WAN operation.<\/span><\/p>\n<h3><b>Question 280<\/b><\/h3>\n<p><b>Which combination can provide secure branch connectivity, dynamic path selection, and quality-based failover?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPsec VPN, SD-WAN rules, and Performance SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP, DNS, and ARP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP, SNMP, and SMTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT, FTP, and HTTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IPsec VPN, SD-WAN rules, and Performance SLA provide complementary capabilities for secure and intelligent WAN connectivity. IPsec can provide encrypted overlay tunnels between branch FortiGates. SD-WAN rules determine how matching traffic should be steered across available members. Performance SLA evaluates the quality and reachability of those paths using metrics such as latency, jitter, packet loss, or availability. When a preferred path becomes degraded, the SD-WAN strategy can select another eligible member. Together, these technologies provide secure connectivity, policy-based traffic steering, and dynamic response to changing WAN conditions.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE6_SDW_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 261 Which SD-WAN component determines whether a monitored WAN path meets configured quality thresholds? Performance SLA Firewall Policy FortiAnalyzer DHCP Server Correct Answer: 1 Explanation Performance SLA evaluates the quality and availability of monitored SD-WAN paths against configured thresholds. Depending on the health-check [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17090"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17090"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17090\/revisions"}],"predecessor-version":[{"id":17091,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17090\/revisions\/17091"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17090"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17090"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17090"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}