[Dec 02, 2021] Step by Step Guide to Prepare for NSE7_SDW-6.4 Exam BrainDumps [Q11-Q34]

Share

Dec 02, 2021 Step by Step Guide to Prepare for NSE7_SDW-6.4 Exam BrainDumps

NSE 7 Network Security Architect NSE7_SDW-6.4 Real Exam Questions and Answers FREE Updated on 2021


Fortinet NSE7_SDW-6.4 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Central management
  • Configure SD-WAN SLAs
Topic 2
  • Configure SD-WAN routing
  • SD-WAN troubleshooting
Topic 3
  • Troubleshoot central management problems
  • Troubleshoot SD-WAN
Topic 4
  • Configure SD-WAN rules
  • Troubleshoot VPN and ADVPN
Topic 5
  • Centrally manage an SD-WAN infrastructure from FortiManager
  • Configure basic SD-WAN setup
Topic 6
  • Implement a full or partially meshed redundant VPN infrastructure
  • SD-WAN configuration

 

NEW QUESTION 11
An administrator is troubleshooting VoIP quality issues that occur when calling external phone numbers The SD-WAN interface on the edge FortiGate is configured with the default settings, and is using two upstream links One link has random jitter and latency issues and is based on a wireless connection Which two actions must the administrator apply simultaneously on the edge FortiGate to improve VoIP quality using SD_WAN rules?

  • A. Select the corresponding SD-WAN balancing strategy in the SD-WAN rule
  • B. Use the performance SLA targets to detect latency and jitter instantly.
  • C. Place the troublesome link at the top of the interface preference list.
  • D. Configure an SD-WAN rule to load balance all traffic without VoIP
  • E. Choose the suitable interface based on the interface cost and weight

Answer: B,E

 

NEW QUESTION 12
An administrator is troubleshooting VoIP quality issues that occur when calling external phone numbers The SD-WAN interface on the edge FortiGate is configured with the default settings, and is using two upstream links One link has random jitter and latency issues and is based on a wireless connection Which two actions must the administrator apply simultaneously on the edge FortiGate to improve VoIP quality using SD_WAN rules?

  • A. Select the corresponding SD-WAN balancing strategy in the SD-WAN rule.
  • B. Use the performance SLA targets to detect latency and jitter instantly.
  • C. Configure an SD-WAN rule to load balance all traffic without VoIP.
  • D. Place the troublesome link at the top of the interface preference list.
  • E. Choose the suitable interface based on the interface cost and weight.

Answer: A,B

 

NEW QUESTION 13
Which two statements reflect the benefits of implementing the ADVPN solution to replace conventional VPN topologies? (Choose two )

  • A. It creates redundant tunnels between hub-and-spokes, in case failure takes place on the primary links
  • B. It ensures that spoke-to-spoke traffic no longer needs to flow through the tunnels through the hub
  • C. It provides direct connectivity between all sites by creating on-demand tunnels between spokes.
  • D. It dynamically assigns cost and weight between the hub and the spokes, based on the physical distance

Answer: A,B

 

NEW QUESTION 14
Which two reasons make forward error correction (FEC) ideal to enable in a phase one VPN interface? (Choose two )

  • A. FEC is useful to increase speed at which traffic is routed through IPsec tunnels.
  • B. FEC improves reliability which overcomes adverse WAN conditions such as noisy links.
  • C. FEC transmits additional packets as redundant data to the remote device.
  • D. FEC transmits the original payload in full to recover the error in transmission.
  • E. FEC reduces the stress on the remote device jitter buffer to reconstruct packet loss

Answer: B,C

 

NEW QUESTION 15
Refer to the exhibit.

Which statement about the command route-tag in the SD-WAN rule is true?

  • A. It uses route tags for a BGP community and assigns the SD-WAN rules with same tag.
  • B. It enables the SD-WAN rule to load balance and assign traffic with a route tag
  • C. It ensures route tags match the SD-WAN rule based on the rule order
  • D. It tags each route and references the tag in the routing table.

Answer: C

 

NEW QUESTION 16
Which statement defines how a per-IP traffic shaper of 10 Mbps is applied to the entire network?

  • A. Each IP is guaranteed a minimum 10 Mbps of bandwidth
  • B. The 10 Mbps bandwidth is shared equally among the IP addresses.
  • C. FortiGate allocates each IP address a maximum 10 Mbps of bandwidth.
  • D. A single user uses the allocated bandwidth divided by total number of users.

Answer: C

 

NEW QUESTION 17
What is the lnkmtd process responsible for?

  • A. Flushing route tags addresses
  • B. Logging interface quality information
  • C. Monitoring links for any bandwidth saturation
  • D. Processing performance SLA probes

Answer: C

 

NEW QUESTION 18
Refer to exhibits.
Exhibit A.

Exhibit B.

Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SO-WAN interface and the static routes configuration.
Port1 and port2 are member interfaces of the SD-WAN, and port2 becomes a dead member after reaching the failure thresholds Which statement about the dead member is correct?

  • A. Dead members require manual administrator access to bring them back alive
  • B. SD-WAN interface becomes disabled and port1 becomes the WAN interface
  • C. Port2 might become alive when a single response is received from an SLA server
  • D. Subnets 100 .64-1.0/23 and 172 . 20 . 0. 0/16 are reachable only through port1

Answer: B

 

NEW QUESTION 19
Refer to the exhibit.

Which two statements about the debug output are correct? (Choose two )

  • A. The debug output shows per-lP shaper values and real-time readings.
  • B. Traffic being controlled by the traffic shaper is under 1 Kbps
  • C. FortiGate provides statistics and readings based on historical traffic logs.
  • D. This traffic shaper drops traffic that exceeds the set limits.

Answer: A,C

 

NEW QUESTION 20
Which diagnostic command can you use to show the SD-WAN rules interface information and state?

  • A. diagnose sys virtual-wan-link route-tag-list
  • B. diagnose sys virtual-wan-link neighbor.
  • C. diagnose sys virtual-wan-link member.
  • D. diagnose sys virtual-wan-link service

Answer: C

 

NEW QUESTION 21
Which two statements describe how IPsec phase 1 main mode is different from aggressive mode when performing IKE negotiation? (Choose two )

  • A. A total of six packets are exchanged between an initiator and a responder instead of three packets.
  • B. The use of Diffie Hellman keys is limited by the responderand needs initiator acceptance
  • C. XAuth is enabled as an additional level of authentication which requires a username and password
  • D. A peer ID is included in the first packet from the initiator, along with suggested security policies

Answer: C

 

NEW QUESTION 22
Which statement is correct about the SD-WAN and ADVPN?

  • A. Spoke support dynamic VPN as a static interface.
  • B. ADVPN interface can be a member of SD-WAN interface.
  • C. Dynamic VPN is not supported as an SD-Wan interface.
  • D. Hub FortiGate is limited to use ADVPN as SD-WAN member interface.

Answer: C

 

NEW QUESTION 23
Refer to exhibits.


Exhibit A shows the source NAT global setting and exhibit B shows the routing table on FortiGate.
Based on the exhibits, which two statements about increasing the port2 interface priority to 20 are true? (Choose two.)

  • A. All the existing sessions will be blocked from using port1 and port2.
  • B. All the existing sessions that do not use SNAT will be flushed and routed through port1.
  • C. All the existing sessions using SNAT will be flushed and routed through port1.
  • D. All the existing sessions will continue to use port2, and new sessions will use port1.

Answer: C,D

 

NEW QUESTION 24
Refer to the exhibit.

Based on the output shown in the exhibit, which two criteria on the SD-WAN member configuration can be used to select an outgoing interface in an SD-WAN rule? (Choose two.)

  • A. Set priority 10.
  • B. Set cost 15.
  • C. Set source 100.64.1.1.
  • D. Set load-balance-mode source-ip-ip-based.

Answer: C

 

NEW QUESTION 25
What would best describe the SD-WAN traffic shaping mode that bases itself on a percentage of available bandwidth?

  • A. Reverse policy shaping mode
  • B. Interface-based shaping mode
  • C. Per-IP shaping mode
  • D. Shared policy shaping mode

Answer: D

 

NEW QUESTION 26
What are two roles that SD-WAN orchestrator plays when it works with FortiManager? (Choose two )

  • A. It configures and monitors SD-WAN networks on FortiGate devices that are managed by FortiManager.
  • B. It acts as an application that is released and signed by Fortinet to run as a part of management extensions on FortiManager.
  • C. It acts as a standalone device to assist FortiManager to manage SD-WAN interfaces on the managed FortiGate devices.
  • D. It acts as a hub FortiGate with an SD-WAN interface enabled and managed along with other FortiGate devices by FortiManager.

Answer: B,C

 

NEW QUESTION 27
Refer to exhibits.
Exhibit A.

Exhibit B.

Exhibit A, which shows the SD-WAN performance SLA and exhibit B shows the health of the participating SD-WAN members.
Based on the exhibits, which statement is correct?

  • A. The dead member interface stays unavailable until an administrator manually brings the interface back.
  • B. Check interval is the time to wait before a packet sent by a member interface considered as lost.
  • C. Port2 needs to wait 500 milliseconds to change the status from alive to dead.
  • D. The SLA state of port2 has exceeded three consecutive unanswered requests from the SLA server.

Answer: D

 

NEW QUESTION 28
Refer to the exhibit.

FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN.
Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces? (Choose two.)

  • A. Use unique Diffie Hellman groups on each VPN interface.
  • B. Configure the IKE mode to be aggressive mode.
  • C. Use different proposals are used between the interfaces.
  • D. Specify a unique peer ID for each dial-up VPN interface.

Answer: A,C

 

NEW QUESTION 29
Refer to the exhibit.

Which statement about the command route-tag in the SD-WAN rule is true?

  • A. It uses route tags for a BGP community and assigns the SD-WAN rules with same tag.
  • B. It enables the SD-WAN rule to load balance and assign traffic with a route tag
  • C. It ensures route tags match the SD-WAN rule based on the rule order
  • D. It tags each route and references the tag in the routing table.

Answer: C

 

NEW QUESTION 30
Refer to exhibits.
Exhibit A.

Exhibit B.

Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SO-WAN interface and the static routes configuration.
Port1 and port2 are member interfaces of the SD-WAN, and port2 becomes a dead member after reaching the failure thresholds Which statement about the dead member is correct?

  • A. Dead members require manual administrator access to bring them back alive
  • B. Port2 might become alive when a single response is received from an SLA server
  • C. SD-WAN interface becomes disabled and port1 becomes the WAN interface
  • D. Subnets 100 .64.1.0/23 and 172 . 20 . 0. 0/16 are reachable only through port1

Answer: D

 

NEW QUESTION 31
Which diagnostic command you can use to show interface-specific SLA logs for the last 10 minutes?

  • A. diagnose sys virtual-wan-link sla-lcg
  • B. diagnose sys virtual-wan-link log
  • C. diagnose sys virtual-wan-link health-check
  • D. diagnose sys virtual-wan-link intf-sla-log

Answer: C

 

NEW QUESTION 32
Which statement reflects how BGP tags work with SD-WAN rules?

  • A. VPN topologies are formed using only BGP dynamic routing with SD-WAN
  • B. BGP tags match the SD-WAN rule based on the order that these rules were installed.
  • C. Route tags are used for a BGP community and the SD-WAN rules are assigned the same tag
  • D. BGP tags require that the adding of static routes be enabled on all ADVPN interfaces

Answer: B

 

NEW QUESTION 33
Refer to exhibits.


Exhibit A shows the performance SLA exhibit B shows the SD-WAN diagnostics output.
Based on the exhibits, which statement is correct?

  • A. Both SD-WAN member interfaces have used separate SLA targets.
  • B. The SLA state of port1 is dead after five unanswered requests by the SLA servers.
  • C. Port1 became dead 1ecause no traffic was offload through the egress of port1.
  • D. SD-WAN member interfaces are affected by the SLA state of the inactive interface

Answer: B

 

NEW QUESTION 34
......

Ultimate Guide to Prepare NSE7_SDW-6.4 Certification Exam for NSE 7 Network Security Architect: https://www.validvce.com/NSE7_SDW-6.4-exam-collection.html

NSE7_SDW-6.4 Ultimate Study Guide: https://drive.google.com/open?id=1gjwOCckVrKIqgrSA7pCP9SIkl7iqU72v