Refer to the exhibits, which show the configuration of an SD-WAN rule and the corresponding rule status and routing table.   The administrator wants to understand the expected behavior for traffic matching the SD-WAN rule. Based on the exhibits, what can the administrator expect for traffic matching the SD-WAN rule?
-
A
The traffic will be routed over HUB1-VPN3.
-
B
The traffic will be routed over HUB1-VPN2
-
C
The traffic will be routed over HUB1-VPN1.
-
D
The traffic will be load balanced across all three overlays
Reveal answer details
Close answer details
Correct answerB
ExplanationThe rule is in SLA mode with two SLAs. From the status, HUB1-VPN2 and HUB1-VPN3 meet the SLA (sla (0x2) and sla(0x3)), while HUB1-VPN1 does not (sla(0x0)). Among members that meet SLA, FortiGate uses the configured order (priority-members 4 5 6) to pick the first eligible one--HUB1-VPN2--so traffic is routed over HUB1-VPN2.
Question 2
Multiple choice
Refer to the exhibits.   An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in the first exhibit. After generating GoToMeeting test traffic, the administrator examined the corresponding traffic log on FortiAnalyzer, which is shown in the second exhibit. The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1. Which two reasons explain why some log messages show that the traffic matched the implicit SD-WAN rule? (Choose two.)
-
A
Full SSL inspection is not enabled on the matching firewall policy.
-
B
The session 3-tuple did not match any of the existing entries in the ISDB application cache.
-
C
FortiGate could not refresh the routing information on the session after the application was detected.
-
D
No configured SD-WAN rule matches the traffic related to the collaboration application GoToMeeting
Reveal answer details
Close answer details
Question 3
Multiple choice
As an MSSP administrator, you are asked to configure ADVPN on an existing SD-WAN topology. FortiManager manages the customer devices in a dedicated ADOM. The previous administrator used the SD-WAN overlay topology. Which two statements apply to this scenario? (Choose two.)
-
A
You can activate auto-discovery VPN in the SD-WAN overlay template only if it is a single hub topology.
-
B
When auto-discovery VPN is enabled, FortiManager updates the IPsec and BGP templates in the hub.
-
C
After you enable auto-discovery VPN in the overlay template, you must select between ADVPN 2.0 and ADVPN 1.0.
-
D
You can activate auto-discovery VPN in the SD-WAN overlay template for any type of topology, including a primary-primary dual-hub topology.
Reveal answer details
Close answer details
Correct answersB, D
ExplanationWhen you enable ADVPN (auto-discovery VPN) in the overlay template, FortiManager automatically updates both the IPsec and BGP templates on the hub so that shortcut tunnels can be established dynamically. ADVPN can be activated in the SD-WAN overlay template for any supported topology, including dual-hub primary-primary, not just single hub.
Question 4
Multiple choice
Exhibit.  Two hub-and-spoke groups are connected through redundant site-to-site IPsec VPNs between Hub 1 and Hub Which two configuration settings are required for the spoke A1 to establish an ADVPN shortcut with the spoke B2? (Choose two.)
-
A
On hubs, auto-discovery-forwarder must be enabled on the IPsec VPNs to hubs.
-
B
On hubs, auto-discovery-receiver must be enabled on the IPsec VPNs to spokes.
-
C
On hubs, auto-discovery-forwarder must be enabled on the IPsec VPNs to spokes.
-
D
On hubs, auto-diacovery-sender must be enabled on the IPsec VPNs to spokes
Reveal answer details
Close answer details
Correct answersA, D
ExplanationTo allow spokes in different hub-and-spoke groups to establish ADVPN shortcuts, the hubs must be configured to forward and send ADVPN shortcut offers. The key required settings on the hub are auto-discovery-forwarder (for VPNs to hubs) and auto-discovery-sender (for VPNs to spokes). This ensures the hub can facilitate and advertise ADVPN shortcut offers between spokes. References: [FCSS_SDW_AR-7.4 1-0.docx Q1] Fortinet SD-WAN 7.4 ADVPN Guide (Auto-discovery settings for hub-and-spoke topologies)
Question 5
Multiple choice
Which three characteristics apply to provisioning templates available on FortiManager? (Choose three.)
-
A
A template group can include a system template and an SD-WAN template.
-
B
Each template group can contain up to three IPsec tunnel templates.
-
C
CLI templates are applied in order, from top to bottom
-
D
A CLI template group can contain CLI templates of both types.
-
E
A CLI template can be of type CLI script or Perl script.
Reveal answer details
Close answer details
Correct answersA, C, D
ExplanationThe provisioning templates in FortiManager are designed for flexible, scalable configuration of large SD-WAN deployments. The official documentation explains: "Template groups can consist of both system and SD-WAN templates, providing a way to apply consistent settings across multiple devices. CLI templates are evaluated and executed in order from top to bottom within the template group, which is crucial for managing dependencies. Furthermore, CLI template groups can contain both regular CLI templates and advanced (Perl-script-based) templates, allowing complex or conditional configuration logic." This modular design streamlines large deployments by separating system, SD-WAN, and CLI logic into reusable building blocks. References: [FCSS_SDW_AR-7.4 1-0.docx Q17] FortiManager Administration Guide 7.4, "Template Groups and CLI Template Processing"
Question 6
Multiple choice
Refer to the exhibits. Exhibit A  Exhibit B  Exhibit A shows the SD-WAN performance SLA configuration, the SD-WAN rule configuration, and the application IDs of Facebook and YouTube. Exhibit B shows the firewall policy configuration and the underlay zone status. Based on the exhibits, which two statements are correct about the health and performance of port1 and port2? (Choose two.)
-
A
The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.
-
B
FortiGate is unable to measure jitter and packet loss on Facebook and YouTube traffic.
-
C
FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.
-
D
Non-TCP Facebook and YouTube traffic are not used for performance measurement.
Reveal answer details
Close answer details
Correct answersA, D
ExplanationStudy Guide 7.2, pages 103 - 104. Another comment said "because without using application Control on the firewall policy, SDWAN can't work" but there is a app control "default" defined on config.
Refer to the exhibits.   The exhibits show the SD-WAN zone configuration of an SD-WAN template prepared on FortiManager and the policy package configuration. When the administrator tries to install the configuration changes, FortiManager fails to commit. What should the administrator do to fix the issue?
-
A
Configure branch1_fgt as the installation target for policy 3.
-
B
Configure HUB1 as the destination of policy 3.
-
C
Configure a normalized interface for the IPsec tunnel HUB1-VPN1.
-
D
Configure both HUB1-VPN1 and HUB1-VPN2 as the destination of policy 3
Reveal answer details
Close answer details
Correct answerB
ExplanationPolicy 3 points traffic To = HUB1-VPN1, which is an SD-WAN member interface. In SD-WAN you must reference the SD-WAN zone (the logical interface) in policies, not its member tunnels. Change the policy's To interface to the zone HUB1, and the install will succeed.
Refer to the exhibit.  Which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules?
-
A
All traffic from a source IP to a destination IP is sent to the same interface.
-
B
All traffic from a source IP is sent to the same interface.
-
C
All traffic from a source IP is sent to the most used interface.
-
D
All traffic from a source IP to a destination IP is sent to the least used interface.
Reveal answer details
Close answer details
Question 9
Multiple choice
Refer to the exhibits.    The exhibits show the configuration for SD-WAN performance. SD-WAN rule, the application IDs of Facebook and YouTube along with the firewall policy configuration and the underlay zone status. Which two statements are true about the health and performance of SD-WAN members 3 and 4? (Choose two.)
-
A
Only related TCP traffic is used for performance measurement.
-
B
The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.
-
C
Encrypted traffic is not used for the performance measurement.
-
D
FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.
Reveal answer details
Close answer details
Question 10
Multiple choice
SD-WAN interacts with many other FortiGate features. Some of them are required to allow SD-WAN to steer the traffic. Which three configuration elements that you must configure before FortiGate can steer traffic according to SD-WAN rules? (Choose three.)
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Correct answersA, B, E
ExplanationBefore FortiGate can steer traffic according to SD-WAN rules, certain configuration elements must be present. The guide states: "SD-WAN is not a standalone feature and interacts with several fundamental FortiGate configurations. Specifically, you must: (1) Define the interfaces (physical, VLAN, or IPsec) that will act as SD-WAN members, (2) Create firewall policies to allow traffic to be steered by SD-WAN, and (3) Set up routing so that traffic has valid routes via SD-WAN members. Without these, SD-WAN rules will not be able to match or steer any traffic." Security profiles and traffic shaping are not mandatory for basic SD-WAN steering but can be layered on for enhanced security and QoS once foundational elements are present. References: [FCSS_SDW_AR-7.4 1-0.docx Q16] FortiOS 7.4 SD-WAN Concept Guide, "Prerequisite Configuration Elements for SD-WAN Steering
Question 11
Multiple choice
Refer to the exhibit.  An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over HUB1-VPN1. However, the traffic is routed over HUB1-VPN3. Based on the output shown in the exhibit, which two reasons, individually or together, could explain the observed behavior? (Choose two.)
-
A
HUB1-VPN3 has a higher member configuration priority than HUB1-VPN1.
-
B
The traffic matches a regular policy route configured with HUB1-VPN3 as the outgoing device
-
C
HUB1-VPN1 does not have a valid route to the destination
-
D
HUB1-VPN3 has a lower route priority value (higher priority) than HUB1-VPN1.
Reveal answer details
Close answer details
Question 12
Multiple choice
What are two common use cases for remote internet access (RIA)? (Choose two.)
-
A
Provide direct internet access on spokes
-
B
Provide internet access through the hub
-
C
Centralize security inspection on the hub
-
D
Provide thorough inspection on spokes
Reveal answer details
Close answer details
Correct answersA, B, C
ExplanationProvide internet access through the hub: This involves routing branch or remote office internet traffic through a central hub, ensuring consistent security policies and possibly better management of network resources. Centralize security inspection on the hub: With this approach, all internet-bound traffic from various spokes is inspected at the hub, leveraging centralized security mechanisms for thorough inspection and policy enforcement.
Question 13
Single choice
Within the context of SD-WAN, what does SIA correspond to?
-
A
-
B
-
C
-
D
Secure Internet Authorization
Reveal answer details
Close answer details
Question 14
Single choice
Refer to the exhibit.  Which action will FortiGate take if it detects SD-WAN members as dead?
-
A
FoftiGate bounces port5 after it detects all SD-WAN members as dead.
-
B
FortiGate fails over to the secondary device after it detects port5 as dead.
-
C
FortiGate sends alert messages through poft5 when it detects all SD-WAN members as dead
-
D
FortiGate brings down port5 after it detects all SD-WAN members as dead.
Reveal answer details
Close answer details
|