売れ筋トップクラスのNSE7_SDW-7.0最新試験問題2024年最新のFortinet試験練習 [Q41-Q64]

Share

売れ筋トップクラスのNSE7_SDW-7.0最新試験問題2024年最新のFortinet試験練習

NSE 7 Network Security Architect問題集でNSE7_SDW-7.0試験は完全版問題で試験学習ガイド


Fortinet NSE7_SDW-7.0認定試験は、ITプロフェッショナルにFortinet SD-Wan Technologiesの専門知識を紹介する機会を提供するベンダー固有の認定です。認定試験は、ネットワーク管理者、セキュリティの専門家、および日々の運用でFortinet Technologiesと協力するソリューションアーキテクト向けに設計されています。

 

質問 # 41
Which diagnostic command can you use to show the member utilization statistics measured by performance SLAs for the last 10 minutes?

  • A. diagnose sys sdwan intf-sla-log
  • B. diagnose sys sdwan health-check
  • C. diagnose sys sdwan log
  • D. diagnose sys sdwan sla-log

正解:D

解説:
SD-WAN 7.2 Study Guide page 321 You can view the stored member metrics by running the diagnose sys sdwan sla-log command. Note that you must include the name of the performance SLA followed by the member configuration index number. To display the SLA logs per interface, you run the diagnose sys sdwan intf-sla-log command.


質問 # 42
Which diagnostic command can you use to show the configured SD-WAN zones and their assigned members?

  • A. diagnose sys sdwan zone
  • B. diagnose sys sdwan interface
  • C. diagnose sys sdwan service
  • D. diagnose sys sdwan member

正解:A


質問 # 43
Which two interfaces are considered overlay links? (Choose two.)

  • A. LAG
  • B. Physical
  • C. IPsec
  • D. GRE

正解:C、D


質問 # 44
Refer to the exhibit.

The exhibit shows the SD-WAN rule status and configuration.
Based on the exhibit, which change in the measured latency will make T_MPLS_0 the new preferred member?

  • A. When T_N1PLS_0 has a latency of 80 ms.
  • B. When T_INET_0_0 has a latency of 250 ms.
  • C. When T_MPLS_0 has a latency of 100 ms.
  • D. When T_INET_0_0 and T_MPLS_0 have the same latency.

正解:A


質問 # 45
Refer to the exhibit, which shows the IPsec phase 1 configuration of a spoke.

What must you configure on the IPsec phase 1 configuration for ADVPN to work with SD-WAN?

  • A. You must set ike-version to 1.
  • B. You must enable auto-discovery-sender.
  • C. You must enable net-device.
  • D. You must disable idle-timeout.

正解:C


質問 # 46
Refer to the exhibit, which shows the IPsec phase 1 configuration of a spoke.

What must you configure on the IPsec phase 1 configuration for ADVPN to work with SD-WAN?

  • A. You must set ike-version to 1.
  • B. You must enable auto-discovery-sender.
  • C. You must enable net-device.
  • D. You must disable idle-timeout.

正解:C


質問 # 47
Refer to the exhibits.


An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in exhibit A.
After generating GoToMeeting test traffic, the administrator examined the respective traffic log on FortiAnalyzer, which is shown in exhibit B.
The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.
Which two reasons explain why the traffic matched the implicit SD-WAN rule? (Choose two.)

  • A. Full SSL inspection is not enabled on the matching firewall policy.
  • B. The session 3-tuple did not match any of the existing entries in the ISDB application cache.
  • C. Port1 and port2 do not have a valid route to the destination.
  • D. FortiGate did not refresh the routing information on the session after the application was detected.

正解:A、D


質問 # 48
Which two statements are correct when traffic matches the implicit SD-WAN rule? (Choose two.)

  • A. Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.
  • B. All SD-WAN rules have the default setting enabled.
  • C. The sdwan_service_id flag in the session information is 0.
  • D. Traffic does not match any of the entries in the policy route table.

正解:C、D

解説:
sdwan_service_id is 0 = match SD-WAN implicit rule, study guide 7.0 page 120, 7.2 page 149 SD-WAN rules internally are interpreted as a Policy route, so when the traffic doesn't match with any policy route, it will be flowing by implict policy.


質問 # 49

Which two conclusions for traffic that matches the traffic shaper are true? (Choose two.)

  • A. The measured bandwidth is less than 100 KBps.
  • B. The traffic shaper drops packets if the bandwidth exceeds 6250 KBps.
  • C. The traffic shaper limits the bandwidth of each source IP to a maximum of 6250 KBps.
  • D. The traffic shaper drops packets if the bandwidth is less than 2500 KBps.

正解:A、B


質問 # 50
Refer to the exhibit.

The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate appliance that supports hardware offloading. Based on the information shown in the exhibits, which two statements about the session are true? (Choose two.)

  • A. The original direction of the symmetric traffic flows from port3 to port2.
  • B. The main session cannot be offloaded to hardware.
  • C. The auxiliary session can be offloaded to hardware.
  • D. The reply direction of the asymmetric traffic flows from port2 to port3.

正解:C、D


質問 # 51
Refer to the exhibit.

Based on the output, which two conclusions are true? (Choose two.)

  • A. The all_rules rule represents the implicit SD-WAN rule.
  • B. Entry 1(id=1) is a regular policy route.
  • C. The SD-WAN rules take precedence over regular policy routes.
  • D. There is more than one SD-WAN rule configured.

正解:B、D


質問 # 52
What is a benefit of using application steering in SD-WAN?

  • A. You do not need to enable SSL inspection.
  • B. The traffic always skips the regular policy routes.
  • C. You do not need to configure firewall policies that accept the SD-WAN traffic.
  • D. You steer traffic based on the detected application.

正解:D


質問 # 53
Which two protocols in the IPsec suite are most used for authentication and encryption? (Choose two.)

  • A. Encapsulating Security Payload (ESP)
  • B. Security Association (SA)
  • C. Internet Key Exchange (IKE)
  • D. Secure Shell (SSH)

正解:A、C


質問 # 54
Refer to the exhibit.

An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over T_INET_0_0. However, the traffic is routed over T_INET_1_0.
Based on the output shown in the exhibit, which two reasons can cause the observed behavior? (Choose two.)

  • A. The traffic matches a regular policy route configured with T_INET_1_0 as the outgoing device.
  • B. T_INET_1_0 has a lower route priority value (higher priority) than T_INET_0_0.
  • C. T_INET_1_0 has a higher member configuration priority than T_INET_0_0.
  • D. T_INET_0_0 does not have a valid route to the destination.

正解:A、D

解説:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Assigning-Priority-to-SD-WAN-Members-for-Default/ta-p/230911


質問 # 55
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows a site-to-site topology between two FortiGate devices: branch1_fgt and dc1_fgt. Exhibit B shows the system global and system settings configuration on dc1_fgt.
When branch1_client establishes a connection to dc1_host, the administrator observes that, on dc1_fgt, the reply traffic is routed over T_INET_0_0, even though T_INET_1_0 is the preferredmember in the matching SD-WAN rule.
Based on the information shown in the exhibits, what configuration change must be made on dc1_fgt so dc1_fgt routes the reply traffic over T_INET_1_0?

  • A. Enable snat-route-change under config system global.
  • B. Disable tp-session-without-syn under config system settings.
  • C. Disable allow-subnet-overlap under config system settings.
  • D. Enable auxiliary-session under config system settings.

正解:D

解説:
Explanation
Controlling return path with auxiliary session When multiple incoming or outgoing interfaces are used in ECMP or for load balancing, changes to routing, incoming, or return traffic interfaces impacts how an existing sessions handles the traffic. Auxiliary sessions can be used to handle these changes to traffic patterns.https://docs.fortinet.com/document/fortigate/7.0.11/administration-guide/14295/controlling-return-path-


質問 # 56
Refer to the exhibit.

An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over T_INET_0_0. However, the traffic is routed over T_INET_1_0.
Based on the output shown in the exhibit, which two reasons can cause the observed behavior? (Choose two.)

  • A. The traffic matches a regular policy route configured with T_INET_1_0 as the outgoing device.
  • B. T_INET_1_0 has a lower route priority value (higher priority) than T_INET_0_0.
  • C. T_INET_1_0 has a higher member configuration priority than T_INET_0_0.
  • D. T_INET_0_0 does not have a valid route to the destination.

正解:A、D


質問 # 57
What are two reasons for using FortiManager to organize and manage the network for a group of FortiGate devices? (Choose two )

  • A. It sends probe signals as health checks to the beacon servers on behalf of FortiGate.
  • B. It reduces WAN usage on FortiGate devices by acting as a local FortiGuard server.
  • C. It simplifies the deployment and administration of SD-WAN on managed FortiGate devices.
  • D. It improves SD-WAN performance on the managed FortiGate devices.
  • E. It acts as a policy compliance entity to review all managed FortiGate devices.

正解:B、C


質問 # 58
Which CLI command do you use to perform real-time troubleshooting for ADVPN negotiation?

  • A. get ipsec tunnel list
  • B. get router info routing-table all
  • C. diagnose debug application ike
  • D. diagnose vpn tunnel list

正解:C

解説:
IKE real-time debug - useful when debugging ADVPN shortcut messages and spoke-to-spoke negotiations.
* diagnose debug console timestamp enable
* diagnose vpn ike log filter clear
* diagnose vpn ike log filter mdst-addr4 <ip.of.hub> <ip.of.spoke>
* diagnose debug application ike -1
* diagnose debug enable


質問 # 59

Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2. The administrator configured ADVPN on both hub-and-spoke groups.
Which two outcomes are expected if a user in Toronto sends traffic to London? (Choose two.)

  • A. Toronto needs to establish a site-to-site tunnel with Hub 2 to bypass Hub 1.
  • B. London generates an IKE information message that contains the Toronto public IP address.
  • C. Traffic from Toronto to London triggers the dynamic negotiation of a direct site-to-site VPN.
  • D. The first packets from Toronto to London are routed through Hub 1 then to Hub 2.

正解:C、D


質問 # 60
Refer to the exhibits.
Exhibit A

Exhibit B -

Exhibit A shows the configuration for an SD-WAN rule and exhibit B shows the respective rule status, the routing table, and the member status.
The administrator wants to understand the expected behavior for traffic matching the SD-WAN rule.
Based on the exhibits, what can the administrator expect for traffic matching the SD-WAN rule?

  • A. The traffic will be load balanced across all three overlays.
  • B. The traffic will be routed over T_INET_1_0.
  • C. The traffic will be routed over T_MPLS_0.
  • D. The traffic will be routed over T_INET_0_0.

正解:C


質問 # 61
Refer to the exhibit.

Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2.
Which two configuration settings are required for Toronto and London spokes to establish an ADVPN shortcut? (Choose two.)

  • A. On the hubs, auto-discovery-sender must be enabled on the IPsec VPNs to spokes.
  • B. auto-discovery-forwarder must be enabled on all IPsec VPNs.
  • C. On the hubs, net-device must be enabled on all IPsec VPNs.
  • D. On the spokes, auto-discovery-receiver must be enabled on the IPsec VPN to the hub.

正解:A、D


質問 # 62
Refer to the exhibit.

Which statement about the role of the ADVPN device in handling traffic is true?

  • A. Two hubs, 10.0.1.101 and 10.0.2.101, are receiving and forwarding queries between each other.
  • B. This is a spoke that has received a query from a remote hub and has forwarded the response to its hub.
  • C. This is a hub that has received a query from a spoke and has forwarded it to another spoke.
  • D. Two spokes, 192.2.0.1 and 10.0.2.101, forward their queries to their hubs.

正解:C


質問 # 63
Refer to the exhibit.

Which conclusion about the packet debug flow output is correct?

  • A. The original traffic exceeded the maximum bandwidth of the outgoing interface, and the packet was dropped.
  • B. The reply traffic exceeded the maximum bandwidth configured in the traffic shaper, and the packet was dropped.
  • C. The original traffic exceeded the maximum bandwidth configured in the traffic shaper, and the packet was dropped.
  • D. The original traffic exceeded the maximum packets per second of the outgoing interface, and the packet was dropped.

正解:C


質問 # 64
......

最善な方法で問題集を使おう!練習テストならこれFortinet NSE7_SDW-7.0:https://www.goshiken.com/Fortinet/NSE7_SDW-7.0-mondaishu.html

NSE7_SDW-7.0問題集を無料提供しております!試験問題と解答:https://drive.google.com/open?id=1a9_BbpJGVkttOXK_XoDxgZGNuSLJqBjg