合格目指せNSE7_SDW-7.0試験最新のNSE7_SDW-7.0試験問題集PDF 2024年更新 [Q26-Q46]

Share

合格目指せNSE7_SDW-7.0試験最新のNSE7_SDW-7.0試験問題集PDF 2024年更新

NSE7_SDW-7.0試験問題集、365日更新無料サンプル

質問 # 26
Which two statements are true about using SD-WAN to steer local-out traffic? (Choose two.)

  • A. By default, FortiGate does not check if the selected member has a valid route to the destination.
  • B. You must configure each local-out feature individually, to use SD-WAN.
  • C. FortiGate does not consider the source address of the packet when matching an SD-WAN rule for local-out traffic.
  • D. By default, local-out traffic does not use SD-WAN.

正解:B、D


質問 # 27
Which diagnostic command can you use to show the member utilization statistics measured by performance SLAs for the last 10 minutes?

  • A. diagnose sys sdwan sla-log
  • B. diagnose sys sdwan health-check
  • C. diagnose sys sdwan log
  • D. diagnose sys sdwan intf-sla-log

正解:A

解説:
SD-WAN 7.2 Study Guide page 321 You can view the stored member metrics by running the diagnose sys sdwan sla-log command. Note that you must include the name of the performance SLA followed by the member configuration index number. To display the SLA logs per interface, you run the diagnose sys sdwan intf-sla-log command.


質問 # 28
Refer to the exhibit.

The device exchanges routes using IBGP.
Which two statements are correct about the IBGP configuration and routing information on the device?
(Choose two.)

  • A. Each BGP route is three hops away from the destination.
  • B. additional-path is enabled.
  • C. You can run the get router info routing-table database command to display the additional paths.
  • D. ibgp-multipath is disabled.

正解:B、C


質問 # 29
What are two reasons why FortiGate would be unable to complete the zero-touch provisioning process? (Choose two.)

  • A. A factory reset performed on FortiGate.
  • B. FortiDeploy has connected with FortiGate and provided the initial configuration to contact FortiManager
  • C. The zero-touch provisioning process has completed internally, behind FortiGate.
  • D. FortiGate has obtained a configuration from the platform template in FortiGate cloud.
  • E. The FortiGate cloud key has not been added to the FortiGate cloud portal.

正解:C、E


質問 # 30
Which two performance SLA protocols enable you to verify that the server response contains a specific value? (Choose two.)

  • A. dns
  • B. http
  • C. icmp
  • D. twamp

正解:A、B

解説:
Pages 85,86 in Study guide 7.0 Pages 100,101 in Study guide 7


質問 # 31
Refer to the exhibit.

The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate appliance that supports hardware offloading. Based on the information shown in the exhibits, which two statements about the session are true? (Choose two.)

  • A. The auxiliary session can be offloaded to hardware.
  • B. The main session cannot be offloaded to hardware.
  • C. The reply direction of the asymmetric traffic flows from port2 to port3.
  • D. The original direction of the symmetric traffic flows from port3 to port2.

正解:A、C


質問 # 32
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows a site-to-site topology between two FortiGate devices: branch1_fgt and dc1_fgt. Exhibit B shows the system global and system settings configuration on dc1_fgt.
When branch1_client establishes a connection to dc1_host, the administrator observes that, on dc1_fgt, the reply traffic is routed over T_INET_0_0, even though T_INET_1_0 is the preferred member in the matching SD-WAN rule.
Based on the information shown in the exhibits, what configuration change must be made on dc1_fgt so dc1_fgt routes the reply traffic over T_INET_1_0?

  • A. Enable snat-route-change under config system global.
  • B. Enable auxiliary-session under config system settings.
  • C. Disable allow-subnet-overlap under config system settings.
  • D. Disable tcp-session-without-syn under config system settings.

正解:B

解説:
Controlling return path with auxiliary session When multiple incoming or outgoing interfaces are used in ECMP or for load balancing, changes to routing, incoming, or return traffic interfaces impacts how an existing sessions handles the traffic. Auxiliary sessions can be used to handle these changes to traffic patterns.https://docs.fortinet.com/document/fortigate/7.0.11/administration-guide/14295/controlling-return-path-with-auxiliary-session


質問 # 33
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SD-WAN member status, the routing table, and the performance SLA status.
If port2 is detected dead by FortiGate, what is the expected behavior?

  • A. Host 8.8.8.8 is reachable through port1 and port2.
  • B. Port2 becomes alive after three successful probes are detected.
  • C. The administrator manually restores the static routes for port2, if port2 becomes alive.
  • D. FortiGate removes all static routes for port2.

正解:D

解説:
This is due to Update static route is enable which removes the static route entry referencing the interface if the interface is dead


質問 # 34
Refer to the exhibit.

Which two SD-WAN template member settings support the use of FortiManager meta fields? (Choose two.)

  • A. Interface member
  • B. Cost
  • C. Priority
  • D. Gateway IP

正解:A、D


質問 # 35
Refer to the exhibit.

Based on the output shown in the exhibit, which two criteria on the SD-WAN member configuration can be used to select an outgoing interface in an SD-WAN rule? (Choose two.)

  • A. Set load-balance-mode source-ip-ip-based.
  • B. Set source 100.64.1.1.
  • C. Set priority 10.
  • D. Set cost 15.

正解:C、D


質問 # 36
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows the traffic shaping policy and exhibit B shows the firewall policy.
The administrator wants FortiGate to limit the bandwidth used by YouTube. When testing, the administrator determines that FortiGate does not apply traffic shaping on YouTube traffic.
Based on the policies shown in the exhibits, what configuration change must be made so FortiGate performs traffic shaping on YouTube traffic?

  • A. Individual SD-WAN members must be selected as the outgoing interface on the traffic shaping policy.
  • B. Web filtering must be enabled on the firewall policy.
  • C. Destination internet service must be enabled on the traffic shaping policy.
  • D. Application control must be enabled on the firewall policy.

正解:D


質問 # 37
In a hub-and-spoke topology, what are two advantages of enabling ADVPN on the IPsec overlays? (Choose two.)

  • A. It provides direct connectivity between spokes by creating shortcuts.
  • B. It enables spokes to bypass the hub during shortcut negotiation.
  • C. It provides the benefits of a full-mesh topology in a hub-and-spoke network.
  • D. It enables spokes to establish shortcuts to third-party gateways.

正解:A、C


質問 # 38
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SD-WAN member status, the routing table, and the performance SLA status.
If port2 is detected dead by FortiGate, what is the expected behavior?

  • A. Host 8.8.8.8 is reachable through port1 and port2.
  • B. Port2 becomes alive after three successful probes are detected.
  • C. The administrator manually restores the static routes for port2, if port2 becomes alive.
  • D. FortiGate removes all static routes for port2.

正解:D

解説:
Explanation
This is due to Update static route is enable which removes the static route entry referencing the interface if the interface is dead


質問 # 39
Which are two benefits of using CLI templates in FortiManager? (Choose two.)

  • A. You can configure FortiManager to sync local configuration changes made on the managed device, to the CLI template.
  • B. You can configure advanced CLI settings.
  • C. You can reference meta fields.
  • D. You can configure interfaces as SD-WAN members without having to remove references first.

正解:B、C


質問 # 40
Refer to the exhibit.

Which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules?

  • A. All traffic from a source IP is sent to the same interface.
  • B. All traffic from a source IP is sent to the most used interface.
  • C. All traffic from a source IP to a destination IP is sent to the same interface.
  • D. All traffic from a source IP to a destination IP is sent to the least used interface.

正解:C


質問 # 41
Refer to the exhibits.


Which two statements about the IPsec VPN configuration and the status of the IPsec VPN tunnel are true? (Choose two.)

  • A. FortiGate does not install IPsec static routes for remote protected networks in the routing table.
  • B. The phase 1 configuration supports the network-overlay setting.
  • C. Dead peer detection is disabled.
  • D. FortiGate facilitated the negotiation of the T_INET_1_0_0 ADVPN shortcut over T_INET_1_0.

正解:A、B


質問 # 42
Exhibit.

Which conclusion about the packet debug flow output is correct?

  • A. The packet size exceeded the outgoing interface MTU.
  • B. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the firewall policy, and the packet was dropped.
  • C. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
  • D. The total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.

正解:C


質問 # 43
Which two statements about SLA targets and SD-WAN rules are true? (Choose two.)

  • A. SD-WAN rules use SLA targets to check if the preferred members meet the SLA requirements.
  • B. SLA targets are used only by SD-WAN rules that are configured with Lowest Cost (SLA) or Maximize Bandwidth (SLA) as strategy.
  • C. When configuring an SD-WAN rule, you can select multiple SLA targets of the same performance SLA.
  • D. Member metrics are measured only if an SLA target is configured.

正解:A、B


質問 # 44
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows the traffic shaping policy and exhibit B shows the firewall policy.
The administrator wants FortiGate to limit the bandwidth used by YouTube. When testing, the administrator determines that FortiGate does not apply traffic shaping on YouTube traffic.
Based on the policies shown in the exhibits, what configuration change must be made so FortiGate performs traffic shaping on YouTube traffic?

  • A. Individual SD-WAN members must be selected as the outgoing interface on the traffic shaping policy.
  • B. Web filtering must be enabled on the firewall policy.
  • C. Destination internet service must be enabled on the traffic shaping policy.
  • D. Application control must be enabled on the firewall policy.

正解:D


質問 # 45
Refer to the exhibit.

Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?

  • A. mode-cfg must be enabled.
  • B. add-route must be disabled.
  • C. type must be set to static.
  • D. exchange-interface-ip must be enabled.

正解:B

解説:
for using "non ike" routes (for example BGP/static and so on) you must do disable the add-route that inject automatically kernel route based on p2 selectors from the remote site from the SD-WAN_7.2_Study_Guide page 236


質問 # 46
......

NSE7_SDW-7.0問題集、あなたを合格させる認証試験:https://www.goshiken.com/Fortinet/NSE7_SDW-7.0-mondaishu.html

まもなくセール終了!リアルNSE7_SDW-7.0のPDF解答を使おう:https://drive.google.com/open?id=17R6fQf9P1cI8XtYzJtihin_Hin3tILMf