New Year Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Fortinet > Fortinet Certified Solution Specialist > FCSS_SDW_AR-7.6

FCSS_SDW_AR-7.6 FCSS - SD-WAN 7.6 Architect Question and Answers

Question # 4

(Refer to the exhibits.

You collected the output shown in the exhibits and want to know which interface HTTP traffic will flow through from the user device 10.0.1.101 to the corporate web server 10.0.0.126. All SD-WAN links are stable.

Which interface will FortiGate use to steer the traffic? Choose one answer.)

A.

Only HUB1-VPN3

B.

Only HUB1-VPN2

C.

Either HUB1-VPN2 or HUB1-VPN3

D.

Either HUB1-VPN1, HUB1-VPN2, or HUB1-VPN3

Full Access
Question # 5

(You configure the overlay tunnels for an SD-WAN hub-and-spoke topology defined with IPsec tunnels, BGP on loopback, and dynamic BGP.

Which are two recommended IPsec settings for this topology? Choose two answers.)

A.

On the spoke, set the parameter net-device to enable.

B.

On the spoke, configure the parameter localid.

C.

On the hub, set the parameter mode-cfg to enable.

D.

On the hub, set the tunnel type to static.

Full Access
Question # 6

Exhibit.

Refer to the exhibit, which shows an SD-WAN zone configuration on the FortiGate GUI. What can you conclude about the zone and member configuration on this device?

A.

The underlay zone contains three members.

B.

You can delete the virtual-wan-link zones.

C.

The overlay-factories zone contains no member.

D.

You can move HUB1-VPN3 from the HUB1 zone to the overlay-shops zone.

Full Access
Question # 7

(Which two features must you configure before FortiGate can steer traffic according to SD-WAN rules? Choose two answers.)

A.

Security profiles

B.

Underlay links

C.

Overlay links

D.

Traffic shaping

E.

Firewall policies

Full Access
Question # 8

Exhibit.

Two hub-and-spoke groups are connected through redundant site-to-site IPsec VPNs between Hub 1 and Hub 2

Which two configuration settings are required for the spoke A1 to establish an ADVPN shortcut with the spoke B2? (Choose two.)

A.

On hubs, auto-discovery-forwarder must be enabled on the IPsec VPNs to hubs.

B.

On hubs, auto-discovery-receiver must be enabled on the IPsec VPNs to spokes.

C.

On hubs, auto-discovery-forwarder must be enabled on the IPsec VPNs to spokes.

D.

On hubs, auto-diacovery-sender must be enabled on the IPsec VPNs to spokes

Full Access
Question # 9

(Refer to the exhibit.

What can you conclude from the output shown? Choose one answer.)

A.

It is a spoke device. SD-WAN rule 3 is configured with nine members.

B.

It is a spoke device. The members of SD-WAN rule 3 are grouped into two zones.

C.

It is a hub device. It allowed the establishment of three auto-discovery VPN (ADVPN) shortcuts.

D.

It is a spoke device. SD-WAN rule 4 allows three shortcut tunnels.

Full Access
Question # 10

(Refer to the exhibits. You collected the output shown in the exhibits and want to know which interface TCP traffic will flow through from the user device 10.0.1.101 to the corporate file server 10.0.0.125. All SD-WAN links are stable.

Which interface will FortiGate use to steer the traffic? Choose one answer.)

A.

Only HUB1-VPN1

B.

Either HUB1-VPN1 or HUB1-VPN2

C.

Only HUB1-VPN2

D.

Either HUB1-VPN1, HUB1-VPN2, or HUB1-VPN3

Full Access
Question # 11

Refer to the exhibits.

The exhibits show the SD-WAN zone configuration of an SD-WAN template prepared on FortiManager and the policy package configuration.

When the administrator tries to install the configuration changes, FortiManager fails to commit.

What should the administrator do to fix the issue?

A.

Configure branch1_fgt as the installation target for policy 3.

B.

Configure HUB1 as the destination of policy 3.

C.

Configure a normalized interface for the IPsec tunnel HUB1-VPN1.

D.

Configure both HUB1-VPN1 and HUB1-VPN2 as the destination of policy 3

Full Access
Question # 12

(In which order does FortiGate consider the following elements during the route lookup process? Choose one answer.)

A.

SD-WAN rules, ISDB routes, policy routes, BGP routes

B.

Policy routes, SD-WAN rules, Internet Service Database (ISDB) routes, BGP routes

C.

SD-WAN rules, policy routes, static routes, ISDB routes

D.

Policy routes, ISDB routes, SD-WAN rules, static routes

Full Access
Question # 13

The FortiGate devices are managed by ForliManager, and are configured for direct internet access (DIA). You confirm that DIA is working as expected for each branch, and check the SD-WAN zone configuration and firewall policies shown in the exhibits.

Then, you use the SD-WAN overlay template to configure the IPsec overlay tunnels. You create the associated SD-WAN rules to connect existing branches to the company hub device and apply the changes on the branches.

After those changes, users complain that they lost internet access. DIA is no longer working.

Based on the exhibit, which statement best describes the possible root cause of this issue?

A.

The SD-WAN overlay template defines a zone for each underlay interface and moves the interfaces into those zones.

B.

The SD-WAN overlay template didn’t configure a firewall policy to allow traffic through the overlay.

C.

The SD-WAN overlay template redefines the interface gateway addresses if they are defined with metadata variables.

D.

The SD-WAN overlay template updates the SD-WAN template and the rules.

Full Access
Question # 14

Refer to the exhibit that shows event logs on FortiGate.

Based on the output shown in the exhibit, what can you say about the tunnels on this device?

A.

The master tunnel HU82-VPN3 cannot accept ADVPN shortcuts.

B.

The device steers voice traffic through the VPN tunnel HUB1-VPN3.

C.

The VPN tunnel HUB1-VPN1_0 is a shortcut tunnel.

D.

There is one shortcut tunnel built from master tunnel VPN4.

Full Access
Question # 15

(As an IT manager, you want to delegate the installation and management of your SD-WAN deployment to a managed security service provider (MSSP). Each site must maintain direct internet access and be secure. You expect significant traffic flow between the sites and want to delegate as much of the network administration and management as possible to the MSSP.

Which two MSSP deployment blueprints address your requirements? Choose two answers.)

A.

Use a shared hub on the MSSP premises and a dedicated hub on the customer premises, and install the spokes on the customer premises.

B.

Install a dedicated hub on the MSSP premises for the customer, and install the spokes on the customer premises.

C.

Install the hub and spokes on the customer premises, and enable the MSSP to manage the SD-WAN deployment using FortiManager with a dedicated ADOM.

D.

Use a shared hub on the MSSP premises with a dedicated VDOM for the customer, and install the spokes on the customer premises.

Full Access
Question # 16

You configured an SD-WAN rule with the best quality strategy and selected the predefined health check, Default_FortiGuard, to check the link performances against FortiGuard servers.

For the quality criteria, you selected Custom-profile-1.

Which factors does FortiGate use, and in which order. to determine the link that it should use to steer the traffic?

A.

Latency – Member configuration order – Link cost threshold

B.

Link quality index – Member configuration order – Link cost threshold

C.

Links that meet the SLA targets – Member configuration order – Member local cost

D.

Latency – Jitter - Packet loss – Bibandwidth – Member configuration order

Full Access
Question # 17

The administrator uses the FortiManager SD-WAN overlay template to prepare an SD-WAN deployment. Using information provided through the SD-WAN overlay template wizard, FortiManager creates templates ready to install on the spoke and hub devices.

What are the three templates created by the SD-WAN overlay template for a spoke device? (Choose three.)

A.

Static route template

B.

Rules template

C.

CLI template

D.

BGP template

E.

IPsec tunnel template

Full Access
Question # 18

Within the context of SD-WAN, what does SIA correspond to?

A.

Remote Breakout

B.

Local Breakout

C.

Software Internet Access

D.

Secure Internet Authorization

Full Access
Question # 19

As an MSSP administrator, you are asked to configure ADVPN on an existing SD-WAN topology. FortiManager manages the customer devices in a dedicated ADOM. The previous administrator used the SD-WAN overlay topology.

Which two statements apply to this scenario? (Choose two.)

A.

You can activate auto-discovery VPN in the SD-WAN overlay template only if it is a single hub topology.

B.

When auto-discovery VPN is enabled, FortiManager updates the IPsec and BGP templates in the hub.

C.

After you enable auto-discovery VPN in the overlay template, you must select between ADVPN 2.0 and ADVPN 1.0.

D.

You can activate auto-discovery VPN in the SD-WAN overlay template for any type of topology, including a primary-primary dual-hub topology.

Full Access
Question # 20

Refer to the exhibit.

An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network.

The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over HUB1-VPN1. However, the traffic is routed over HUB1-VPN3.

Based on the output shown in the exhibit, which two reasons, individually or together, could explain the observed behavior? (Choose two.)

A.

HUB1-VPN3 has a higher member configuration priority than HUB1-VPN1.

B.

The traffic matches a regular policy route configured with HUB1-VPN3 as the outgoing device

C.

HUB1-VPN1 does not have a valid route to the destination

D.

HUB1-VPN3 has a lower route priority value (higher priority) than HUB1-VPN1.

Full Access
Question # 21

(Refer to the exhibit.

The event log on a FortiGate device is shown.

Based on the output shown in the exhibit, what can you conclude about the tunnels on this device? (Choose one answer))

A.

There is one shortcut tunnel built from the master tunnel VPN4.

B.

The voice traffic is steered through the VPN tunnel HUB1-VPN3.

C.

The VPN tunnel HUB1-VPN1_0 is a shortcut tunnel.

D.

The master tunnel HUB2-VPN3 cannot accept Auto-Discovery VPN (ADVPN) shortcuts.

Full Access
Question # 22

(Refer to the exhibits.

The SD-WAN zones and members configuration of two branch devices are shown. The two branch devices are part of the same hub-and-spoke topology and connect to the same hub. The devices are configured to allow Auto-Discovery VPN (ADVPN). The configuration on the hub allows the initial communication between the two spokes.

When traffic flows require it, between which interfaces can the devices establish shortcuts? Choose one answer.)

A.

Any interface in the overlay zones

B.

Interface connected to HUB only

C.

Between T3 on Branch-A and TC on Branch-B

D.

Between T2 on Branch-A and TA on Branch-B

Full Access
Question # 23

You manage an SD-WAN topology. You will soon deploy 50 new branches.

Which three tasks can you do in advance to simplify this deployment? (Choose three.)

A.

Update the DHCP server configuration.

B.

Create model devices.

C.

Create a ZTP template.

D.

Define metadata variables value for each device.

E.

Create policy blueprint.

Full Access
Question # 24

(Refer to the exhibit.

You update the spokes configuration of an existing auto-discovery VPN (ADVPN) topology by adding the parameters shown in the exhibit.

Which is a valid objective of those settings? Choose one answer.)

A.

Enable the tunnels as overlay links.

B.

Convert the configuration from ADVPN to ADVPN 2.0.

C.

Prevent cross-overlay shortcuts.

D.

Prevent multiple shortcuts from being established over the same overlay.

Full Access
Question # 25

Refer to the exhibits.

The exhibits show two IPsec templates to define Branch IPsec 1 and Branch_IPsec_2. Each template defines a VPN tunnel. The error message that FortiManager displayed when the administrator tried to assign the second template to the FortiGate device is also shown.

Which statement best describes the cause of the issue?

A.

You can assign only one template with a tunnel type of static to each FortiGate device.

B.

You can assign only one IPsec template to each FortiGate device.

C.

You should review the branch1_fgt configuration for configured tunnels in the rootVDOM.

D.

You should use the same outgoing interface of both templates.

Full Access
Question # 26

(Refer to the exhibit. You noticed that one SD-WAN member went down and you immediately collected the session output shown in the exhibit. What can you conclude from this output? Choose one answer.)

A.

FortiGate didn’t receive any traffic related to this session after the interface went down.

B.

FortiGate flushed the gateway for the session.

C.

FortiGate cannot reevaluate the session.

D.

FortiGate already reevaluated this session.

Full Access
Question # 27

Exhibit.

Refer to the exhibit, which shows the SD-WAN rule status and configuration.

Based on the exhibit, which change in the measured packet loss will make HUB1-VPN3 the new preferred member?

A.

When HUB1-VPN1 has 4% packet loss

B.

When HUB1-VPN1 has 12% packet loss

C.

When HUB1-VPN3 has 4% packet loss

D.

When all three members have the same packet loss

Full Access
Question # 28

(Refer to the exhibit. The administrator configured two SD-WAN rules to load balance the traffic.

Which interfaces does FortiGate use to steer the traffic from 10.0.1.124 to 10.0.0.254? Choose one answer.)

A.

HUB2-VPN2

B.

HUB1-VPN2 or HUB2-VPN2

C.

port1 or port2

D.

Any interface in the HUB1 or HUB2 zones

Full Access