Refer to the exhibit.  Which action will FortiGate take if it detects SD-WAN members as dead?
-
A
FoftiGate bounces port5 after it detects all SD-WAN members as dead.
-
B
FortiGate fails over to the secondary device after it detects port5 as dead.
-
C
FortiGate sends alert messages through poft5 when it detects all SD-WAN members as dead
-
D
FortiGate brings down port5 after it detects all SD-WAN members as dead.
Reveal answer details
Close answer details
Correct answerC
ExplanationThe selected answer is consistent with FortiGate routing order. Normal route lookup must first resolve traffic to an SD-WAN zone or member, and then SD-WAN rules, member status, route tags, source NAT settings, and tie breakers influence the final egress choice. The rejected choices skip part of that sequence or assume SD-WAN can steer traffic independently of the route, member, and policy objects that make the flow eligible.
Question 2
Multiple choice
Which two statements about SD-WAN rules are true? (Choose two.)
-
A
Regular policy routes take precedence over SD-WAN rules.
-
B
SD-WAN rules take precedence over static routes.
-
C
SD-WAN rules can be used only to define load balancing methods.
-
D
SD-WAN rules are treated as static routes.
Reveal answer details
Close answer details
Correct answersA, B
ExplanationThe selected answer is consistent with FortiGate routing order. Normal route lookup must first resolve traffic to an SD-WAN zone or member, and then SD-WAN rules, member status, route tags, source NAT settings, and tie breakers influence the final egress choice. The rejected choices skip part of that sequence or assume SD-WAN can steer traffic independently of the route, member, and policy objects that make the flow eligible.
Refer to the exhibits.    The first exhibit shows the SD-WAN zone HUB1 and SD-WAN member configuration from an SD-WAN template, and the second exhibit shows the output of command diagnose sys sdwan member collected on a FortiGate device. Which statement best describes what the diagnose output shows?
-
A
The diagnose output shows that HUB1-VPN1 and all HUBx-VPNy members are dead.
-
B
The diagnose output does not correspond to a device configured with the SD-WAN template shown in the exhibit.
-
C
The diagnose output was collected on the device branch2_fgt.
-
D
The diagnose output was collected on the device branch1_fgt
Reveal answer details
Close answer details
Correct answerD
ExplanationThe selected answer matches FortiManager SD-WAN orchestration. Templates, blueprints, metadata, ADOM separation, and install workflows prepare repeatable device configuration, but they still depend on required per-device variables and post-run validation. The rejected choices confuse template preparation with completed forwarding behavior or omit information FortiManager needs before it can install consistent SD-WAN, IPsec, policy, and routing objects.
Refer to the exhibit.  The administrator analyzed the traffic between a branch FortiGate and the server located in the data center, and noticed the behavior shown in the diagram. When the LAN clients located behind FGT1 establish a session to a server behind DC-1, the administrator observes that, on DC-1, the reply traffic is routed overT2. even though T1 is the preferred member in the matching SD-WAN rule. What can the administrator do to instruct DC-1 to route the reply traffic through the member with the best performance?
-
A
Enable snat-route-change under config system global.
-
B
Enable reply-session under config system sdwan.
-
C
Enable auxiliary-session under config system settings.
-
D
FortiGate route lookup for reply traffic only considers routes over the original ingress interface.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe selected answer is consistent with FortiGate routing order. Normal route lookup must first resolve traffic to an SD-WAN zone or member, and then SD-WAN rules, member status, route tags, source NAT settings, and tie breakers influence the final egress choice. The rejected choices skip part of that sequence or assume SD-WAN can steer traffic independently of the route, member, and policy objects that make the flow eligible.
Refer to the exhibit.  Which SD-WAN rule and interface uses FortiGate to steer the traffic from the LAN subnet 10.0.1.0/24 to the corporate server 10.2.5.254?
-
A
SD-WAN service rule 3 and interface HUB1-VPN2.
-
B
SD-WAN service rule 3 and interface HUB1-VPN3.
-
C
SD-WAN service rule 4 and port1 or port2.
-
D
SD-WAN service rule 4 and interface port2.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe selected answer matches Fortinet SD-WAN overlay design. Underlay interfaces provide transport, while IPsec tunnels and SD-WAN members form the overlay used by rules and health checks. Correct hub, spoke, template, and tunnel settings are required before traffic can be steered reliably; the rejected choices either mix underlay and overlay roles or assume a tunnel state that the FortiGate configuration would not produce.
Refer to the exhibit.  The event log on a FortiGate device is shown. Based on the output shown in the exhibit, what can you conclude about the tunnels on this device? (Choose one answer))
-
A
There is one shortcut tunnel built from the master tunnel VPN4.
-
B
The voice traffic is steered through the VPN tunnel HUB1-VPN3.
-
C
The VPN tunnel HUB1-VPN1_0 is a shortcut tunnel.
-
D
The master tunnel HUB2-VPN3 cannot accept Auto-Discovery VPN (ADVPN) shortcuts.
Reveal answer details
Close answer details
Correct answerC
ExplanationThe selected answer follows Fortinet ADVPN behavior: the hub advertises reachability and the spokes can build shortcut tunnels only when the overlay, routing, and shortcut authorization parameters are consistent. BGP reachability, loopback or tunnel addressing, and correct phase-1 or phase-2 settings must all agree; otherwise traffic remains on the hub path or the shortcut cannot be used for the desired flows.
Question 7
Multiple choice
Refer to the text area.  The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate device that supports hardware offloading. Based on the information shown in the text area, which two conclusions can you draw? (Choose two.)
-
A
By default, FortiGate offloads symmetric and asymmetric flows.
-
B
The original direction of the symmetric traffic flows from port3 to port2.
-
C
The reply direction of the asymmetric traffic flows from port2 to port3.
-
D
The auxiliary session can be offloaded to hardware.
Reveal answer details
Close answer details
Correct answersB, C
ExplanationThe selected answer follows the diagnostic evidence available from FortiGate and FortiManager. SD-WAN status, event logs, traffic logs, session output, and member counters show the rule, member, tunnel, SLA, and offload state that explain the forwarding decision. The rejected choices infer behavior that is not supported by the status fields or conflict with how FortiGate records SD-WAN rule matching and member selection.
Refer to the exhibit.  You noticed that one SD-WAN member went down and you immediately collected the session output shown in the exhibit. What can you conclude from this output? Choose one answer.
-
A
FortiGate didn't receive any traffic related to this session after the interface went down.
-
B
FortiGate flushed the gateway for the session.
-
C
FortiGate cannot reevaluate the session.
-
D
FortiGate already reevaluated this session.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe selected answer is consistent with FortiGate routing order. Normal route lookup must first resolve traffic to an SD-WAN zone or member, and then SD-WAN rules, member status, route tags, source NAT settings, and tie breakers influence the final egress choice. The rejected choices skip part of that sequence or assume SD-WAN can steer traffic independently of the route, member, and policy objects that make the flow eligible.
Refer to the exhibits.   The administrator configured a device blueprint and CLI scripts as shown in the exhibits, to prepare for onboarding FortiGate devices in the company's stores. Later, a technician prepares a FortiGate 51G with a basic configuration and connects it to the network. The basic configuration contains the port1 configuration and the minimal configuration required to allow the device to connect to FortiManager. After the device first connects to FortiManager, FortiManager updates the device configuration. Based on the exhibits, which actions does FortiManager perform?
-
A
FortiManager updates the device configuration according to the selected templates. It applies the corp_st template first.
-
B
FortiManager does not update the port1 configuration because FortiManager does not change the configuration of interfaces with fgfm access.
-
C
FortiManager updates access rights only for port1. FortiManager cannot update the IP address because it was already set manually.
-
D
FortiManager updates the configuration of port1, port2, and port5. The three ports might get new IP addresses.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe selected answer matches FortiManager SD-WAN orchestration. Templates, blueprints, metadata, ADOM separation, and install workflows prepare repeatable device configuration, but they still depend on required per-device variables and post-run validation. The rejected choices confuse template preparation with completed forwarding behavior or omit information FortiManager needs before it can install consistent SD-WAN, IPsec, policy, and routing objects.
Question 10
Multiple choice
In the default SD-WAN minimum configuration, which two statements are correct when traffic matches the default implicit SD-WAN rule? (Choose two.)
-
A
Traffic has matched none of the FortiGate policy routes.
-
B
Matched traffic failed RPF and was caught by the rule.
-
C
The FIB lookup resolved interface was the SD-WAN interface.
-
D
An absolute SD-WAN rule was defined and matched traffic.
Reveal answer details
Close answer details
Correct answersA, C
ExplanationThe selected answer is consistent with FortiGate routing order. Normal route lookup must first resolve traffic to an SD-WAN zone or member, and then SD-WAN rules, member status, route tags, source NAT settings, and tie breakers influence the final egress choice. The rejected choices skip part of that sequence or assume SD-WAN can steer traffic independently of the route, member, and policy objects that make the flow eligible.
Question 11
Single choice
Refer to the exhibit.  When attempting to establish an IPsec tunnel to FortiGate, all remote users match the FIRST_VPN IPsec VPN. This includes remote users that want to connect to the SECOND_VPN IPsec VPN. Which two configuration changes must you make on both IPsec VPNs so that remote users can connect to their intended IPsec VPN? (Choose two.)
-
A
Configure different proposals.
-
B
Configure a unique peer I
-
C
Change the IKE mode to aggressive.
-
D
Configure different Diffie Hellman groups.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe selected answer matches Fortinet SD-WAN overlay design. Underlay interfaces provide transport, while IPsec tunnels and SD-WAN members form the overlay used by rules and health checks. Correct hub, spoke, template, and tunnel settings are required before traffic can be steered reliably; the rejected choices either mix underlay and overlay roles or assume a tunnel state that the FortiGate configuration would not produce.
Question 12
Single choice
Refer to the exhibit.  Based on the output shown in the exhibit, what can you conclude about the device role and how it handles health checks? Choose one answer.
-
A
The device is a spoke and it provides embedded health-check measures for each tunnel to the hub.
-
B
The device is a spoke and it receives health-check measures for the tunnels of another spoke.
-
C
The device is a hub and it receives embedded health-check measures for each tunnel from the spoke.
-
D
The device is a hub and it receives health-check measures for the tunnels of a spoke.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe selected answer follows how FortiGate evaluates SD-WAN performance SLAs. Health checks measure member quality, passive or active probe mode controls how measurements are learned, and SD-WAN rules then compare the configured quality criteria or cost strategy against eligible members. The rejected choices either ignore member health, use the wrong traffic type for passive measurement, or assume a rule can prefer a link before the SLA and strategy make that member eligible.
Question 13
Multiple choice
Refer to the exhibit.  An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over HUB1-VPN1. However, the traffic is routed over HUB1-VPN3. Based on the output shown in the exhibit, which two reasons, individually or together, could explain the observed behavior? (Choose two.)
-
A
HUB1-VPN3 has a higher member configuration priority than HUB1-VPN1.
-
B
The traffic matches a regular policy route configured with HUB1-VPN3 as the outgoing device
-
C
HUB1-VPN1 does not have a valid route to the destination
-
D
HUB1-VPN3 has a lower route priority value (higher priority) than HUB1-VPN1.
Reveal answer details
Close answer details
Correct answersC, D
ExplanationThe selected answer is consistent with FortiGate routing order. Normal route lookup must first resolve traffic to an SD-WAN zone or member, and then SD-WAN rules, member status, route tags, source NAT settings, and tie breakers influence the final egress choice. The rejected choices skip part of that sequence or assume SD-WAN can steer traffic independently of the route, member, and policy objects that make the flow eligible.
Question 14
Single choice
Refer to the exhibit.  Which statement best describe the role of the ADVPN device in handling traffic?
-
A
This is a hub that has received a query from a spoke and has forwarded it to another spoke.
-
B
This is a hub in a dual-region topology. The remote hub tunnel ID is 10.0.2.101.
-
C
This is a spoke that has received a shortcut query from another spoke and has forwarded the response to its hub.
-
D
This is a spoke. The kernel received a shortcut request and forwards the query to another spoke.
Reveal answer details
Close answer details
Correct answerC
ExplanationThe selected answer follows Fortinet ADVPN behavior: the hub advertises reachability and the spokes can build shortcut tunnels only when the overlay, routing, and shortcut authorization parameters are consistent. BGP reachability, loopback or tunnel addressing, and correct phase-1 or phase-2 settings must all agree; otherwise traffic remains on the hub path or the shortcut cannot be used for the desired flows.
Question 15
Single choice
Refer to the exhibits.   The interface details, static route configuration, and firewall policies on the managed FortiGate device are shown. You want to configure a new SD-WAN zone, named Underlay, that contains the interfaces port1 and port2. What must be your first action?
-
A
Define port1 as an SD-WAN member.
-
B
Delete the static routes.
-
C
Delete the SD-WAN Zone Test.
-
D
Delete the firewall policies.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe selected answer is consistent with FortiGate routing order. Normal route lookup must first resolve traffic to an SD-WAN zone or member, and then SD-WAN rules, member status, route tags, source NAT settings, and tie breakers influence the final egress choice. The rejected choices skip part of that sequence or assume SD-WAN can steer traffic independently of the route, member, and policy objects that make the flow eligible.
Question 16
Multiple choice
A team is using FortiManager to deploy a new SD-WAN overlay to many branches. Which two actions are part of the normal centralized deployment flow after the overlay template is created? (Choose two.)
-
A
Assign required metadata variables, such as unique branch identifiers, to branch devices.
-
B
Configure SD-WAN rules that use the newly created overlay members or zones.
-
C
Delete the FortiManager ADOM before installing the generated templates.
-
D
Disable all device-level template groups because overlay orchestration cannot use them.
-
E
Install FortiClient on the FortiManager server to enable IPsec template generation.
Reveal answer details
Close answer details
Correct answersA, B
ExplanationThe selected answer matches FortiManager SD-WAN orchestration. Templates, blueprints, metadata, ADOM separation, and install workflows prepare repeatable device configuration, but they still depend on required per-device variables and post-run validation. The rejected choices confuse template preparation with completed forwarding behavior or omit information FortiManager needs before it can install consistent SD-WAN, IPsec, policy, and routing objects.
Question 17
Multiple choice
What are three key routing principles of SD-WAN? (Choose three.)
-
A
Directly connected routes have precedence over SD-WAN rules.
-
B
Policy routes have precedence over SD-WAN rules.
-
C
SD-WAN rules are skipped if the best route to the destination is a static route
-
D
SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.
-
E
SD-WAN members are skipped if they do not have a valid route to the destination.
Reveal answer details
Close answer details
Correct answersB, D, E
ExplanationThe selected answer is consistent with FortiGate routing order. Normal route lookup must first resolve traffic to an SD-WAN zone or member, and then SD-WAN rules, member status, route tags, source NAT settings, and tie breakers influence the final egress choice. The rejected choices skip part of that sequence or assume SD-WAN can steer traffic independently of the route, member, and policy objects that make the flow eligible.
|