2024 Current NSE7_SDW-7.2 dumps Preparation through Our Practice Test
100% Reliable Microsoft NSE7_SDW-7.2 Exam Dumps Test Pdf Exam Material
NEW QUESTION # 34
Refer to the exhibit.
Which two SD-WAN template member settings support the use of FortiManager meta fields? (Choose two.)
- A. Gateway IP
- B. Cost
- C. Interface member
- D. Priority
Answer: A,C
NEW QUESTION # 35
Refer to the exhibit.
Based on the output shown in the exhibit, which two criteria on the SD-WAN member configuration can be used to select an outgoing interface in an SD-WAN rule? (Choose two.)
- A. Set source 100.64.1.1.
- B. Set priority 10.
- C. Set cost 15.
- D. Set load-balance-mode source-ip-ip-based.
Answer: B,C
NEW QUESTION # 36
Refer to the exhibit.
An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over T_INET_0_0. However, the traffic is routed over T_INET_1_0.
Based on the output shown in the exhibit, which two reasons can cause the observed behavior? (Choose two.)
- A. T_INET_0_0 does not have a valid route to the destination.
- B. T_INET_1_0 has a lower route priority value (higher priority) than T_INET_0_0.
- C. T_INET_1_0 has a higher member configuration priority than T_INET_0_0.
- D. The traffic matches a regular policy route configured with T_INET_1_0 as the outgoing device.
Answer: A,D
NEW QUESTION # 37
Refer to the exhibit.
Based on the exhibit, which two actions does FortiGate perform on sessions after a firewall policy change?
(Choose two.)
- A. FortiGate terminates the old sessions.
- B. FortiGate does not change existing sessions.
- C. FortiGate flushes all sessions.
- D. FortiGate evaluates new sessions.
Answer: B,D
Explanation:
FortiGate not to flag existing impacted session as dirty by setting firewall-session-dirty to check new. The results is that FortiGate evaluates only new session against the new firewall policy.
NEW QUESTION # 38
Refer to the exhibits.

Exhibit A shows the SD-WAN rule status and the learned BGP routes with community 65000:10.
Exhibit B shows the SD-WAN rule configuration, the BGP neighbor configuration, and the route map configuration.
The administrator wants to steer corporate traffic using routes tags in the SD-WAN rule ID 1.
However, the administrator observes that the corporate traffic does not match the SD-WAN rule ID 1.
Based on the exhibits, which configuration change is required to fix issue?
- A. In the dcl-lab-rm route map configuration, set set-route-tag to 10.
- B. In SD-WAN rule ID 1, change the destination to use ISDB entries.
- C. In the BGP neighbor configuration, apply the route map dcl-lab-rm in the outbound direction.
- D. In the dcl-lab-rm route map configuration, unset match-community.
Answer: C
NEW QUESTION # 39
Refer to the exhibits.
Exhibit A
Exhibit B
Exhibit A shows the SD-WAN performance SLA configuration, the SD-WAN rule configuration, and the application IDs of Facebook and YouTube. Exhibit B shows the firewall policy configuration and the underlay zone status.
Based on the exhibits, which two statements are correct about the health and performance of port1 and port2? (Choose two.)
- A. FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.
- B. FortiGate is unable to measure jitter and packet loss on Facebook and YouTube traffic.
- C. The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.
- D. Non-TCP Facebook and YouTube traffic are not used for performance measurement.
Answer: C,D
Explanation:
Study Guide 7.2, pages 103 - 104. Another comment said "because without using application Control on the firewall policy, SDWAN can't work" but there is a app control "default" defined on config.
NEW QUESTION # 40
Which statement is correct about SD-WAN and ADVPN?
- A. Routes for ADVPN shortcuts must be manually configured.
- B. You must use IKEv2 on IPsec tunnels.
- C. SD-WAN does not monitor the health and performance of ADVPN shortcuts.
- D. SD-WAN can steer traffic to ADVPN shortcuts, established over IPsec overlays, configured as SD-WAN members.
Answer: D
NEW QUESTION # 41
Refer to the exhibit.
An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over T_INET_0_0. However, the traffic is routed over T_INET_1_0.
Based on the output shown in the exhibit, which two reasons can cause the observed behavior? (Choose two.)
- A. T_INET_0_0 does not have a valid route to the destination.
- B. T_INET_1_0 has a lower route priority value (higher priority) than T_INET_0_0.
- C. T_INET_1_0 has a higher member configuration priority than T_INET_0_0.
- D. The traffic matches a regular policy route configured with T_INET_1_0 as the outgoing device.
Answer: A,D
NEW QUESTION # 42
Which two statements about SD-WAN central management are true? (Choose two.)
- A. It does not allow you to monitor the status of SD-WAN members.
- B. It is enabled or disabled on a per-ADOM basis.
- C. It is enabled by default.
- D. It uses templates to configure SD-WAN on managed devices.
Answer: B,D
NEW QUESTION # 43
Refer to the exhibit.
In a dual-hub hub-and-spoke SD-WAN deployment, which is a benefit of disabling the anti-replay setting on the hubs?
- A. It instructs the hub to skip content inspection on TCP traffic, to improve performance.
- B. It instructs the hub to disable the reordering of TCP packets on behalf of the receiver, to improve performance.
- C. It instructs the hub to disable TCP sequence number check, which is required for TCP sessions originated from spokes to fail over back and forth between the hubs.
- D. It instructs the hub to not check the ESP sequence numbers on IPsec traffic, to improve performance.
Answer: C
NEW QUESTION # 44
Refer to the exhibits.

An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in exhibit A.
After generating GoToMeeting test traffic, the administrator examined the respective traffic log on FortiAnalyzer, which is shown in exhibit B.
The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.
Which two reasons explain why the traffic matched the implicit SD-WAN rule? (Choose two.)
- A. Port1 and port2 do not have a valid route to the destination.
- B. FortiGate did not refresh the routing information on the session after the application was detected.
- C. The session 3-tuple did not match any of the existing entries in the ISDB application cache.
- D. Full SSL inspection is not enabled on the matching firewall policy.
Answer: B,C
Explanation:
Study guide 7.2 Page 191
NEW QUESTION # 45
Which diagnostic command can you use to show the configured SD-WAN zones and their assigned members?
- A. diagnose sys sdwan service
- B. diagnose sys sdwan interface
- C. diagnose sys sdwan member
- D. diagnose sys sdwan zone
Answer: D
NEW QUESTION # 46
Refer to the exhibit.
Based on the exhibit, which statement about FortiGate re-evaluating traffic is true?
- A. Firewall policy ID 1 has source NAT disabled.
- B. The type of traffic defined and allowed on firewall policy ID 1 is UDP.
- C. Changes have been made on firewall policy ID 1 on FortiGate.
- D. FortiGate has terminated the session after a change on policy ID 1.
Answer: C
NEW QUESTION # 47
The SD-WAN overlay template helps to prepare SD-WAN deployments. To complete the tasks performed by
the SD-WAN overlay template, the administrator must perform some post-run tasks. What are three
mandatory post-run tasks that must be performed? (Choose three.)
- A. Configure routing through overlay tunnels created by the SD-WAN overlay template.
- B. Configure SD-WAN rules.
- C. Assign an sdwan_id metadata variable to each device (branch and hub}.
- D. Create policy packages for branch devices.
- E. Assign a branch_id metadata variable to each branch device.
Answer: A,C,D
NEW QUESTION # 48
Which two statements are correct when traffic matches the implicit SD-WAN rule? (Choose two.)
- A. The sdwan_service_id flag in the session information is 0.
- B. All SD-WAN rules have the default setting enabled.
- C. Traffic does not match any of the entries in the policy route table.
- D. Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.
Answer: A,C
Explanation:
sdwan_service_id is 0 = match SD-WAN implicit rule, study guide 7.0 page 120, 7.2 page 149 SD-WAN rules internally are interpreted as a Policy route, so when the traffic doesn't match with any policy route, it will be flowing by implict policy.
NEW QUESTION # 49
Which two statements are true about using SD-WAN to steer local-out traffic? (Choose two.)
- A. By default, local-out traffic does not use SD-WAN.
- B. You must configure each local-out feature individually, to use SD-WAN.
- C. By default, FortiGate does not check if the selected member has a valid route to the destination.
- D. FortiGate does not consider the source address of the packet when matching an SD-WAN rule for local-out traffic.
Answer: A,B
NEW QUESTION # 50
Refer to the exhibits.

An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in exhibit A.
After generating GoToMeeting test traffic, the administrator examined the respective traffic log on FortiAnalyzer, which is shown in exhibit B. The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.
Which two reasons explain why the traffic matched the implicit SD-WAN rule? (Choose two.)
- A. Port1 and port2 do not have a valid route to the destination.
- B. FortiGate did not refresh the routing information on the session after the application was detected.
- C. The session 3-tuple did not match any of the existing entries in the ISDB application cache.
- D. Full SSL inspection is not enabled on the matching firewall policy.
Answer: B,C
Explanation:
Study guide 7.2 Page 191
NEW QUESTION # 51
Refer to the exhibit.
Which statement explains the output shown in the exhibit?
- A. FortiGate performed standard FIB routing on the session.
- B. FortiGate used 192.2.0.1 as the gateway for the original direction of the traffic.
- C. FortiGate will not re-evaluate the session following a firewall policy change.
- D. FortiGate must re-evaluate the session due to routing change.
Answer: D
Explanation:
The snat-route-change option is enabled by default. This option enables FortiGate to re-evaluate the routing table and select a new egress interface if the next hop IP address changes. This option only applies to sessions in the dirty state. Sessions in the log state are not affected by routing changes.
NEW QUESTION # 52
Refer to the exhibit.
Which statement about the role of the ADVPN device in handling traffic is true?
- A. This is a hub that has received a query from a spoke and has forwarded it to another spoke.
- B. Two hubs,10.0.1.101and10.0.2.101, are receiving and forwarding queries between each other.
- C. This is a spoke that has received a query from a remote hub and has forwarded the response to its hub.
- D. Two spokes,192.2.0.1and10.0.2.101, forward their queries to their hubs.
Answer: A
NEW QUESTION # 53
Refer to the exhibit.
The exhibit shows the SD-WAN rule status and configuration.
Based on the exhibit, which change in the measured packet loss will make T_INET_1_0 the new preferred member?
- A. When T_INET_0_0 has 12% packet loss.
- B. When T_INET_1_0 has 4% packet loss.
- C. When T_INET_0_0 has 4% packet loss.
- D. When all three members have the same packet loss.
Answer: B
NEW QUESTION # 54
Refer to the exhibit.
Based on the exhibit, which action does FortiGate take?
- A. FortiGate bounces port5 after it detects all SD-WAN members as dead.
- B. FortiGate brings up port5 after it detects all SD-WAN members as alive.
- C. FortiGate brings down port5 after it detects all SD-WAN members as dead.
- D. FortiGate fails over to the secondary device after it detects all SD-WAN members as dead.
Answer: D
NEW QUESTION # 55
Refer to the exhibits.
Exhibit A -
Exhibit B -
Exhibit A shows the traffic shaping policy and exhibit B shows the firewall policy.
The administrator wants FortiGate to limit the bandwidth used by YouTube. When testing, the administrator determines that FortiGate does not apply traffic shaping on YouTube traffic.
Based on the policies shown in the exhibits, what configuration change must be made so FortiGate performs traffic shaping on YouTube traffic?
- A. Application control must be enabled on the firewall policy.
- B. Web filtering must be enabled on the firewall policy.
- C. Individual SD-WAN members must be selected as the outgoing interface on the traffic shaping policy.
- D. Destination internet service must be enabled on the traffic shaping policy.
Answer: A
NEW QUESTION # 56
Which two performance SLA protocols enable you to verify that the server response contains a specific value?
(Choose two.)
- A. http
- B. icmp
- C. twamp
- D. dns
Answer: A,D
NEW QUESTION # 57
In a hub-and-spoke topology, what are two advantages of enabling ADVPN on the IPsec overlays? (Choose two.)
- A. It provides the benefits of a full-mesh topology in a hub-and-spoke network.
- B. It enables spokes to bypass the hub during shortcut negotiation.
- C. It enables spokes to establish shortcuts to third-party gateways.
- D. It provides direct connectivity between spokes by creating shortcuts.
Answer: A,D
NEW QUESTION # 58
......
Free NSE7_SDW-7.2 Dumps are Available for Instant Access: https://www.actual4exams.com/NSE7_SDW-7.2-valid-dump.html
Based on Official Syllabus Topics of Actual Fortinet NSE7_SDW-7.2 Exam: https://drive.google.com/open?id=1FqbI5fcg6R1OXEdkbPgevInYJfm7u7Lx