A fully updated 2021 NSE7_SDW-6.4 Exam Dumps exam guide from training expert itPass4sure [Q17-Q41]

Share

A fully updated 2021 NSE7_SDW-6.4 Exam Dumps exam guide from training expert itPass4sure

Provides complete coverage of every objective on exam and exam preparation NSE7_SDW-6.4

NEW QUESTION 17
Refer to exhibits.
Exhibit A.

Exhibit B.

Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SO-WAN interface and the static routes configuration.
Port1 and port2 are member interfaces of the SD-WAN, and port2 becomes a dead member after reaching the failure thresholds Which statement about the dead member is correct?

  • A. Subnets 100 .64.1.0/23 and 172 . 20 . 0. 0/16 are reachable only through port1
  • B. Dead members require manual administrator access to bring them back alive
  • C. Port2 might become alive when a single response is received from an SLA server
  • D. SD-WAN interface becomes disabled and port1 becomes the WAN interface

Answer: A

 

NEW QUESTION 18
Refer to the exhibit.

Which two statements about the debug output are correct? (Choose two )

  • A. The debug output shows per-IP shaper values and real-time readings.
  • B. FortiGate provides statistics and reading based on historical traffic logs.
  • C. Traffic being controlled by the traffic shaper is under 1 Kbps.
  • D. This traffic shaper drops traffic that exceeds the set limits.

Answer: A,D

 

NEW QUESTION 19
Refer to exhibits.
Exhibit A.


Exhibit A shows the performance SLA exhibit B shows the SD-WAN diagnostics output Based on the exhibits, which statement is correct?

  • A. SD-WAN member interfaces are affected by the SLA state of the inactive interface
  • B. The SLA state of port1 is dead after five unanswered requests by the SLA servers.
  • C. Port1 became dead 1ecause no traffic was offload through the egress of port1.
  • D. Both SD-WAN member interfaces have used separate SLA targets.

Answer: D

 

NEW QUESTION 20
What are two reasons why FortiGate would be unable to complete the zero-touch provisioning process? (Choose two.)

  • A. The zero-touch provisioning process has completed internally, behind FortiGate.
  • B. A factory reset performed on FortiGate.
  • C. FortiDeploy has connected with FortiGate and provided the initial configuration to contact FortiManager
  • D. The FortiGate cloud key has not been added to the FortiGate cloud portal.
  • E. FortiGate has obtained a configuration from the platform template in FortiGate cloud.

Answer: A,D

 

NEW QUESTION 21
Refer to the exhibit.

Which statement about the trace evaluation by FomGate is true?

  • A. The packet exceeded the configured bandwidth and was dropped based on the priority configuration
  • B. The packet exceeded the configured maximum bandwidth and was dropped by the shared shaper.
  • C. Packets exceeding the configured concurrent connection limit are dropped based on tfte priority configuration.
  • D. Packets exceeding the configured maximum concurrent connection limit are denied by the per-IP shaper.

Answer: C

 

NEW QUESTION 22
Refer to exhibits.


Exhibit A shows the source NAT global setting and exhibit B shows the routing table on FortiGate.
Based on the exhibits, which two statements about increasing the port2 interface priority to 20 are true? (Choose two.)

  • A. All the existing sessions will be blocked from using port1 and port2.
  • B. All the existing sessions using SNAT will be flushed and routed through port1.
  • C. All the existing sessions will continue to use port2, and new sessions will use port1.
  • D. All the existing sessions that do not use SNAT will be flushed and routed through port1.

Answer: B,C

 

NEW QUESTION 23
Refer to the exhibit.

Which statement about the command route-tag in the SD-WAN rule is true?

  • A. It uses route tags for a BGP community and assigns the SD-WAN rules with same tag.
  • B. It enables the SD-WAN rule to load balance and assign traffic with a route tag
  • C. It ensures route tags match the SD-WAN rule based on the rule order
  • D. It tags each route and references the tag in the routing table.

Answer: C

 

NEW QUESTION 24
Refer to the exhibit.

What must you configure to enable ADVPN?

  • A. The protected subnets should be set to address object to all (0.0 .0. o/o).
  • B. ADVPN should only be enabled on unmanaged FortiGate devices.
  • C. On the hub VPN, only the device needs additional phase one sett
  • D. Each VPN device has a unique pre-shared key configured separately on phase one

Answer: D

 

NEW QUESTION 25
Refer to exhibits.
Exhibit A.

Exhibit B.

Exhibit A, which shows the SD-WAN performance SLA and exhibit B shows the health of the participating SD-WAN members.
Based on the exhibits, which statement is correct?

  • A. The SLA state of port2 has exceeded three consecutive unanswered requests from the SLA server.
  • B. Port2 needs to wait 500 milliseconds to change the status from alive to dead.
  • C. Check interval is the time to wait before a packet sent by a member interface considered as lost.
  • D. The dead member interface stays unavailable until an administrator manually brings the interface back.

Answer: A

 

NEW QUESTION 26
Refer to exhibits.


Exhibit A shows the performance SLA exhibit B shows the SD-WAN diagnostics output.
Based on the exhibits, which statement is correct?

  • A. SD-WAN member interfaces are affected by the SLA state of the inactive interface.
  • B. The SLA state of port1 is dead after five unanswered requests by the SLA servers.
  • C. Port1 became dead because no traffic was offload through the egress of port1.
  • D. Both SD-WAN member interfaces have used separate SLA targets.

Answer: B

 

NEW QUESTION 27
Which statement defines how a per-IP traffic shaper of 10 Mbps is applied to the entire network?

  • A. The 10 Mbps bandwidth is shared equally among the IP addresses.
  • B. A single user uses the allocated bandwidth divided by total number of users.
  • C. Each IP is guaranteed a minimum 10 Mbps of bandwidth.
  • D. FortiGate allocates each IP address a maximum 10 Mbps of bandwidth.

Answer: D

Explanation:
Explanation/Reference:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/885253/per-ip-traffic-shaper

 

NEW QUESTION 28
Which statement defines how a per-IP traffic shaper of 10 Mbps is applied to the entire network?

  • A. The 10 Mbps bandwidth is shared equally among the IP addresses.
  • B. A single user uses the allocated bandwidth divided by total number of users.
  • C. Each IP is guaranteed a minimum 10 Mbps of bandwidth
  • D. FortiGate allocates each IP address a maximum 10 Mbps of bandwidth.

Answer: D

 

NEW QUESTION 29
In the default SD-WAN minimum configuration, which two statements are correct when traffic matches the default implicit SD-WAN rule? (Choose two )

  • A. The FIB lookup resolved interface was the SD-WAN member interface
  • B. Matched traffic failed RPF and was caught by the rule.
  • C. An absolute SD-WAN rule was defined and matched traffic
  • D. Traffic has matched none of the FortiGate policy routes

Answer: C,D

 

NEW QUESTION 30
What are two benefits of using FortiManager to organize and manage the network for a group of FortiGate devices? (Choose two.)

  • A. It reduces WAN usage on FortiGate devices by acting as a local FortiGuard server.
  • B. It sends probe signals as health checks to the beacon servers on behalf of FortiGate.
  • C. It improves SD-WAN performance on the managed FortiGate devices.
  • D. It simplifies the deployment and administration of SD-WAN on managed FortiGate devices.
  • E. It acts as a policy compliance entity to review all managed FortiGate devices.

Answer: D,E

 

NEW QUESTION 31
What are two benefits of using FortiManager to organize and manage the network for a group of FortiGate devices? (Choose two )

  • A. It reduces WAN usage on FortiGate devices by acting as a local FortiGuard server.
  • B. It simplifies the deployment and administration of SD-WAN on managed FortiGate devices.
  • C. It sends probe signals as health checks to the beacon servers on behalf of FortiGate.
  • D. It acts as a policy compliance entity to review all managed FortiGate devices.
  • E. It improves SD-WAN performance on the managed FortiGate devices.

Answer: D,E

 

NEW QUESTION 32
What is the lnkmtd process responsible for?

  • A. Flushing route tags addresses
  • B. Monitoring links for any bandwidth saturation
  • C. Logging interface quality information
  • D. Processing performance SLA probes

Answer: B

 

NEW QUESTION 33
What would best describe the SD-WAN traffic shaping mode that bases itself on a percentage of available bandwidth?

  • A. Per-IP shaping mode
  • B. Reverse policy shaping mode
  • C. Shared policy shaping mode
  • D. Interface-based shaping mode

Answer: C

 

NEW QUESTION 34
Which statement about using BGP routes in SD-WAN is true?

  • A. VPN topologies must be form using only BGP dynamic routing with SD-WAN
  • B. Learned routes can be used as dynamic destinations in SD-WAN rules
  • C. Adding static routes must be enabled on all ADVPN interfaces.
  • D. Dynamic routing protocols can be used only with non-encrypted traffic

Answer: A

 

NEW QUESTION 35
Which three parameters are available to configure SD-WAN rules? (Choose three.)

  • A. Internet service database (ISDB) address object
  • B. Type of physical link connection
  • C. URL categories
  • D. Application signatures
  • E. Source and destination IP address

Answer: A,B,E

 

NEW QUESTION 36
Which statement reflects how BGP tags work with SD-WAN rules?

  • A. Route tags are used for a BGP community and the SD-WAN rules are assigned the same tag
  • B. VPN topologies are formed using only BGP dynamic routing with SD-WAN
  • C. BGP tags require that the adding of static routes be enabled on all ADVPN interfaces
  • D. BGP tags match the SD-WAN rule based on the order that these rules were installed.

Answer: B

 

NEW QUESTION 37
Which diagnostic command you can use to show interface-specific SLA logs for the last 10 minutes?

  • A. diagnose sys virtual-wan-link health-check
  • B. diagnose sys virtual-wan-link sla-lcg
  • C. diagnose sys virtual-wan-link intf-sla-log
  • D. diagnose sys virtual-wan-link log

Answer: A

 

NEW QUESTION 38
Refer to exhibits.


Exhibit A shows the SD-WAN rules and exhibit B shows the traffic logs. The SD-WAN traffic logs reflect how FortiGate processed traffic.
Which two statements about how the configured SD-WAN rules are processing traffic are true? (Choose two.)

  • A. The implicit rule overrides all other rules because parameters widely cover sources and destinations.
  • B. SD-WAN rules are evaluated in the same way as firewall policies: from top to bottom.
  • C. The initial session of an application goes through a learning phase in order to apply the correct rule.
  • D. The All_Access_Rules rule load balances Vimeo application traffic among SD-WAN member interfaces.

Answer: A,B

 

NEW QUESTION 39
Which diagnostic command you can use to show interface-specific SLA logs for the last 10 minutes?

  • A. diagnose sys virtual-wan-link health-check
  • B. diagnose sys virtual-wan-link intf-sla-log
  • C. diagnose sys virtual-wan-link sla-log
  • D. diagnose sys virtual-wan-link log

Answer: C

 

NEW QUESTION 40
Which diagnostic command you can use to show interface-specific SLA logs for the last 10 minutes?

  • A. diagnose sys virtual-wan-link health-check
  • B. diagnose sys virtual-wan-link intf-sla-log
  • C. diagnose sys virtual-wan-link sla-log
  • D. diagnose sys virtual-wan-link log

Answer: C

Explanation:
Explanation/Reference: https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/943037/sla-logging

 

NEW QUESTION 41
......

Tested Material Used To NSE7_SDW-6.4: https://www.itpass4sure.com/NSE7_SDW-6.4-practice-exam.html

Steps Necessary To Pass The NSE7_SDW-6.4 Exam: https://drive.google.com/open?id=1r83OGG24LeBsmnXQ0NwPy9dz50GBIiR6