手に入れよう!は2024年最新の有効な実践問題であなたのNSE7_SDW-7.0試験を合格させる(本日更新された70問) [Q20-Q37]

Share

手に入れよう!は2024年最新の有効な実践問題であなたのNSE7_SDW-7.0試験を合格させる(本日更新された70問)

NSE 7 Network Security Architect NSE7_SDW-7.0試験実践テスト問題集解答豪華セットを使おう!

質問 # 20
Which SD-WAN setting enables FortiGate to delay the recovery of ADVPN shortcuts?

  • A. idle-timeout
  • B. hold-down-time
  • C. link-down-failover
  • D. auto-discovery-shortcuts

正解:B


質問 # 21
Which CLI command do you use to perform real-time troubleshooting for ADVPN negotiation?

  • A. get ipsec tunnel list
  • B. diagnose debug application ike
  • C. get router info routing-table all
  • D. diagnose vpn tunnel list

正解:B

解説:
IKE real-time debug - useful when debugging ADVPN shortcut messages and spoke-to-spoke negotiations.
* diagnose debug console timestamp enable
* diagnose vpn ike log filter clear
* diagnose vpn ike log filter mdst-addr4 <ip.of.hub> <ip.of.spoke>
* diagnose debug application ike -1
* diagnose debug enable


質問 # 22
Exhibit.

Which conclusion about the packet debug flow output is correct?

  • A. The total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
  • B. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
  • C. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the firewall policy, and the packet was dropped.
  • D. The packet size exceeded the outgoing interface MTU.

正解:B


質問 # 23
Refer to the exhibit.

Based on the exhibit, which two actions does FortiGate perform on sessions after a firewall policy change?
(Choose two.)

  • A. FortiGate flushes all sessions.
  • B. FortiGate terminates the old sessions.
  • C. FortiGate does not change existing sessions.
  • D. FortiGate evaluates new sessions.

正解:C、D

解説:
Explanation
FortiGate not to flag existing impacted session as dirty by setting firewall-session-dirty to check new. The results is that FortiGate evaluates only new session against the new firewall policy.


質問 # 24
Refer to the exhibits.

Exhibit B -

Exhibit A shows the system interface with the static routes and exhibit B shows the firewall policies on the managed FortiGate.
Based on the FortiGate configuration shown in the exhibits, what issue might you encounter when creating an SD-WAN zone for port1 and port2?

  • A. port1 is assigned a manual IP address.
  • B. port1 and port2 are not administratively down.
  • C. port2 is referenced in a static route.
  • D. port1 is referenced in a firewall policy.

正解:D


質問 # 25
Which two performance SLA protocols enable you to verify that the server response contains a specific value? (Choose two.)

  • A. icmp
  • B. dns
  • C. http
  • D. twamp

正解:B、C

解説:
Pages 85,86 in Study guide 7.0 Pages 100,101 in Study guide 7


質問 # 26
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows the traffic shaping policy and exhibit B shows the firewall policy.
The administrator wants FortiGate to limit the bandwidth used by YouTube. When testing, the administrator determines that FortiGate does not apply traffic shaping on YouTube traffic.
Based on the policies shown in the exhibits, what configuration change must be made so FortiGate performs traffic shaping on YouTube traffic?

  • A. Web filtering must be enabled on the firewall policy.
  • B. Individual SD-WAN members must be selected as the outgoing interface on the traffic shaping policy.
  • C. Application control must be enabled on the firewall policy.
  • D. Destination internet service must be enabled on the traffic shaping policy.

正解:C


質問 # 27
Refer to the exhibit.

FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN.
Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces? (Choose two.)

  • A. Specify a unique peer ID for each dial-up VPN interface.
  • B. Configure the IKE mode to be aggressive mode.
  • C. Use unique Diffie Hellman groups on each VPN interface.
  • D. Use different proposals are used between the interfaces.

正解:A、B


質問 # 28
Which two performance SLA protocols enable you to verify that the server response contains a specific value?
(Choose two.)

  • A. icmp
  • B. dns
  • C. http
  • D. twamp

正解:B、C


質問 # 29
Which two statements about SLA targets and SD-WAN rules are true? (Choose two.)

  • A. SD-WAN rules use SLA targets to check if the preferred members meet the SLA requirements.
  • B. SLA targets are used only by SD-WAN rules that are configured with Lowest Cost (SLA) or Maximize Bandwidth (SLA) as strategy.
  • C. When configuring an SD-WAN rule, you can select multiple SLA targets of the same performance SLA.
  • D. Member metrics are measured only if an SLA target is configured.

正解:A、B


質問 # 30
Refer to the exhibits.

Which conclusion about the packet debug flow output is correct?

  • A. The total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
  • B. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
  • C. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the firewall policy, and the packet was dropped.
  • D. The packet size exceeded the outgoing interface MTU.

正解:B

解説:
In a Per-IP shaper configuration, if an IP address exceeds the configured concurrent session limit, the message "Denied by quota check" appears. SD-WAN 7.0 Study Guide page 287


質問 # 31
Refer to the exhibit.

Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2.
Which two configuration settings are required for Toronto and London spokes to establish an ADVPN shortcut? (Choose two.)

  • A. auto-discovery-forwarder must be enabled on all IPsec VPNs.
  • B. On the spokes, auto-discovery-receiver must be enabled on the IPsec VPN to the hub.
  • C. On the hubs, auto-discovery-sender must be enabled on the IPsec VPNs to spokes.
  • D. On the hubs, net-device must be enabled on all IPsec VPNs.

正解:B、C


質問 # 32
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows a site-to-site topology between two FortiGate devices: branch1_fgt and dc1_fgt. Exhibit B shows the system global and system settings configuration on dc1_fgt.
When branch1_client establishes a connection to dc1_host, the administrator observes that, on dc1_fgt, the reply traffic is routed over T_INET_0_0, even though T_INET_1_0 is the preferredmember in the matching SD-WAN rule.
Based on the information shown in the exhibits, what configuration change must be made on dc1_fgt so dc1_fgt routes the reply traffic over T_INET_1_0?

  • A. Enable snat-route-change under config system global.
  • B. Disable allow-subnet-overlap under config system settings.
  • C. Enable auxiliary-session under config system settings.
  • D. Disable tp-session-without-syn under config system settings.

正解:C

解説:
Explanation
Controlling return path with auxiliary session When multiple incoming or outgoing interfaces are used in ECMP or for load balancing, changes to routing, incoming, or return traffic interfaces impacts how an existing sessions handles the traffic. Auxiliary sessions can be used to handle these changes to traffic patterns.https://docs.fortinet.com/document/fortigate/7.0.11/administration-guide/14295/controlling-return-path-


質問 # 33
Refer to the exhibit.

Based on the exhibit, which action does FortiGate take?

  • A. FortiGate fails over to the secondary device after it detects all SD-WAN members as dead.
  • B. FortiGate bounces port5 after it detects all SD-WAN members as dead.
  • C. FortiGate brings down port5 after it detects all SD-WAN members as dead.
  • D. FortiGate brings up port5 after it detects all SD-WAN members as alive.

正解:A


質問 # 34
Refer to the exhibit.

The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate appliance that supports hardware offloading. Based on the information shown in the exhibits, which two statements about the session are true? (Choose two.)

  • A. The reply direction of the asymmetric traffic flows from port2 to port3.
  • B. The auxiliary session can be offloaded to hardware.
  • C. The original direction of the symmetric traffic flows from port3 to port2.
  • D. The main session cannot be offloaded to hardware.

正解:A、B


質問 # 35
Refer to the exhibit.

The device exchanges routes using IBGP.
Which two statements are correct about the IBGP configuration and routing information on the device?
(Choose two.)

  • A. ibgp-multipath is disabled.
  • B. additional-path is enabled.
  • C. Each BGP route is three hops away from the destination.
  • D. You can run the get router info routing-table database command to display the additional paths.

正解:B、D


質問 # 36
Which two statements about the SD-WAN zone configuration are true? (Choose two.)

  • A. The service-sla-tie-break setting enables you to configure preferred member selection based on the best route to the destination.
  • B. You can delete the default zones.
  • C. An SD-WAN member can belong to two or more zones.
  • D. The default zones are virtual-wan-link and SASE.

正解:A、D


質問 # 37
......

完全版最新の問題集PDFで最新NSE7_SDW-7.0試験問題と解答:https://www.goshiken.com/Fortinet/NSE7_SDW-7.0-mondaishu.html

本日更新された最新のNSE7_SDW-7.0のPDFはNSE7_SDW-7.0無料お試し可能です:https://drive.google.com/open?id=1AHFaJzFyHgW68_3m_tvnrZIsIv649NyA