最新 [2025年01月03日] Fortinet NSE7_SDW-7.2リアル試験問題集PDF [Q29-Q47]

Share

最新 [2025年01月03日] Fortinet NSE7_SDW-7.2リアル試験問題集PDF

NSE7_SDW-7.2練習テスト問題は更新された99問題あります

質問 # 29
In the default SD-WAN minimum configuration, which two statements are correct when traffic matches the default implicit SD-WAN rule? (Choose two )

  • A. Matched traffic failed RPF and was caught by the rule.
  • B. The FIB lookup resolved interface was the SD-WAN interface.
  • C. Traffic has matched none of the FortiGate policy routes.
  • D. An absolute SD-WAN rule was defined and matched traffic.

正解:B、C


質問 # 30
Refer to the exhibit.

In a dual-hub hub-and-spoke SD-WAN deployment, which is a benefit of disabling theanti-replaysetting on
the hubs?

  • A. It instructs the hub to disable TCP sequence number check, which is required for TCP sessions
    originated from spokes to fail over back and forth between the hubs.
  • B. It instructs the hub to not check the ESP sequence numbers on IPsec traffic, to improve performance.
  • C. It instructs the hub to disable the reordering of TCP packets on behalf of the receiver, to improve
    performance.
  • D. It instructs the hub to skip content inspection on TCP traffic, to improve performance.

正解:A


質問 # 31
Refer to the exhibits.


An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in exhibit A.
After generating GoToMeeting test traffic, the administrator examined the respective traffic log on FortiAnalyzer, which is shown in exhibit B.
The administrator noticed that the traffic matched the implicit SD- WAN rule, but they expected the traffic to match rule ID 1.
Which two reasons explain why the traffic matched the implicit SD-WAN rule? (Choose two.)

  • A. Port1 and port2 do not have a valid route to the destination.
  • B. The session 3-tuple did not match any of the existing entries in the ISDB application cache.
  • C. Full SSL inspection is not enabled on the matching firewall policy.
  • D. FortiGate did not refresh the routing information on the session after the application was detected.

正解:A、C


質問 # 32
Refer to the exhibits.
Exhibit A

Exhibit B -

Exhibit A shows the configuration for an SD-WAN rule and exhibit B shows the respective rule status, the routing table, and the member status.
The administrator wants to understand the expected behavior for traffic matching the SD-WAN rule.
Based on the exhibits, what can the administrator expect for traffic matching the SD-WAN rule?

  • A. The traffic will be routed over T_MPLS_0.
  • B. The traffic will be load balanced across all three overlays.
  • C. The traffic will be routed over T_INET_0_0.
  • D. The traffic will be routed over T_INET_1_0.

正解:D


質問 # 33
Refer to the exhibit.

The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants
BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths.
However, when looking at the spoke routing table, the administrator does not see the prefixes from other
spokes and the additional paths.
Based on the exhibit, which three settings must the administrator configure inside each BGP neighbor group so
spokes can learn other spokes prefixes and their additional paths? (Choose three.)

  • A. Setadv-additional-pathto the number of additional paths to advertise
  • B. Enableroute-reflector-client
  • C. Setadvertisement-intervalto the number of additional paths to advertise
  • D. Setadditional-pathtosend
  • E. Enablesoft-reconfiguration

正解:A、B、D


質問 # 34
Which statement about using BGP for ADVPN is true?

  • A. IBGP is preferred over EBGP, because IBGP preserves next hop information.
  • B. You must configure AS path prepending.
  • C. You must use BGP to route traffic for both overlay and underlay links.
  • D. You must configure BGP communities.

正解:A

解説:
ADVPN is a technology that allows dynamic creation of IPsec tunnels between branch sites without requiring pre-configured policies or keys. BGP is a routing protocol that can be used to exchange routes between ADVPN peers. IBGP is a type of BGP that runs between routers in the same autonomous system (AS), while EBGP is a type of BGP that runs between routers in different ASes. IBGP is preferred over EBGP for ADVPN, because IBGP preserves the next hop information of the routes, which is needed to establish the IPsec tunnels. EBGP changes the next hop information to the EBGP peer address, which may not be reachable by the ADVPN peers. Therefore, using IBGP for ADVPN avoids the need to configure additional static routes or redistribute routes between BGP and another routing protocol. References = ADVPN with BGP as the routing protocol, ADVPN, SD-WAN self-healing with BGP, Technical Tip: ADVPN with BGP as the routing protocol The statement that IBGP is preferred over EBGP for ADVPN because IBGP preserves next hop information (D) is true. In a typical ADVPN deployment, it's beneficial to maintain next hop information across the network to ensure proper routing and optimal path selection. References: This understanding comes from my knowledge of Fortinet's SD-WAN and ADVPN configurations, where BGP's behavior in terms of next hop preservation is a key consideration.


質問 # 35
In which SD-WAN template field can you use a metadata variable?

  • A. All SD-WAN template fields support metadata variables.
  • B. Any field Identified with a dollar sign ($) in a magnifying glass.
  • C. You can use metadata variables only to define interface members and the gateway IP.
  • D. Any field identified with an "M" in a circle.

正解:A


質問 # 36
Which two statements are correct when traffic matches the implicit SD-WAN rule? (Choose two.)

  • A. The sdwan_service_id flag in the session information is 0.
  • B. Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.
  • C. Traffic does not match any of the entries in the policy route table.
  • D. All SD-WAN rules have the default setting enabled.

正解:A、C

解説:
sdwan_service_id is 0 = match SD-WAN implicit rule, study guide 7.0 page 120, 7.2 page 149 SD-WAN rules internally are interpreted as a Policy route, so when the traffic doesn't match with any policy route, it will be flowing by implict policy.


質問 # 37
Which action fortigate performs on the traffic that is subject to a per-IP traffic shaper of 10 Mbps?

  • A. FortiGate applies traffic shaping to the original traffic direction only.
  • B. FortiGate shares 10 Mbps of bandwidth equally among all source IP addresses.
  • C. Fortigate limits each source ip address to a maximum bandwidth of 10 Mbps.
  • D. FortiGate guarantees a minimum of 10 Mbps of bandwidth to each source IP address.

正解:C


質問 # 38
Refer to the exhibit.

Based on the exhibit, which two actions does FortiGate perform on sessions after a firewall policy change? (Choose two.)

  • A. FortiGate flushes all sessions.
  • B. FortiGate does not change existing sessions.
  • C. FortiGate evaluates new sessions.
  • D. FortiGate terminates the old sessions.

正解:B、C

解説:
FortiGate not to flag existing impacted session as dirty by setting firewall-session-dirty to check new. The results is that FortiGate evaluates only new session against the new firewall policy.


質問 # 39
Refer to the exhibit.

Based on the exhibit, which action does FortiGate take?

  • A. FortiGate brings up port5 after it detects all SD-WAN members as alive.
  • B. FortiGate bounces port5 after it detects all SD-WAN members as dead.
  • C. FortiGate fails over to the secondary device after it detects all SD-WAN members as dead.
  • D. FortiGate brings down port5 after it detects all SD-WAN members as dead.

正解:C


質問 # 40
Refer to the exhibit.

FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN.
Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces? (Choose two.)

  • A. Specify a unique peer ID for each dial-up VPN interface.
  • B. Use different proposals are used between the interfaces.
  • C. Use unique Diffie Hellman groups on each VPN interface.
  • D. Configure the IKE mode to be aggressive mode.

正解:A、D


質問 # 41
Which statement about SD-WAN zones is true?

  • A. You can configure up to 32 SD-WAN zones per VDOM.
  • B. You cannot use an SD-WAN zone in static route definitions.
  • C. An SD-WAN zone can contain between 0 and 512 members.
  • D. An SD-WAN zone can contain only one type of interface.

正解:A

解説:
Explanation
SD-WAN zones are a group of interfaces that share the same SD-WAN settings, such as health check, SLA,
and load balancing. Some characteristics of SD-WAN zones are:
An SD-WAN zone can contain different types of interfaces, such as physical, VLAN, aggregate, and
tunnel interfaces1.
An SD-WAN zone can contain up to 512 members1.
You can use an SD-WAN zone in static route definitions, as long as the destination interface is also an
SD-WAN zone1.
You can configure up to 32 SD-WAN zones per VDOM1.


質問 # 42
Refer to the exhibit.

The device exchanges routes using IBGP.
Which two statements are correct about the IBGP configuration and routing information on the device? (Choose two.)

  • A. ibgp-multipath is disabled.
  • B. Each BGP route is three hops away from the destination.
  • C. additional-path is enabled.
  • D. You can run the get router info routing-table database command to display the additional paths.

正解:C、D


質問 # 43
Refer to the exhibit.

An administrator used the SD-WAN overlay template to prepare an IPsec configuration for a hub-and-spoke
SD-WAN topology. The exhibit shows the installation preview for one FortiGate device. In the exhibit, which
statement best describes the configuration applied to the FortiGate device?

  • A. It is a hub device and will automatically discover the spoke devices that are in the SD-WAN topology.
  • B. It is a spoke device that establishes dynamic IPsec tunnels to the hub. It can send ADVPN shortcut
    requests.
  • C. It is a hub device. It can send ADVPN shortcut offers.
  • D. It is a spoke device that establishes dynamic IPsec tunnels to the hub. The subnet range is
    10.10.128.0/23.

正解:B

解説:
Explanation
According to the SD-WAN 7.2 Study Guide, the SD-WAN overlay template simplifies the configuration of
IPsec tunnels in a hub-and-spoke topology. The template defines the following parameters:
type: dynamic for spokes, static for hubs
interface: the WAN interface to use for the IPsec tunnel
network-overlay: enable for spokes, disable for hubs
network-id: a unique identifier for each spoke
auto-discovery-sender: enable for hubs, disable for spokes
auto-discovery-receiver: enable for spokes, disable for hubs
Based on the exhibit, the FortiGate device has the following configuration:
type: dynamic
interface: port1
network-overlay: enable
network-id: 5
auto-discovery-sender: disable
auto-discovery-receiver: enable
Therefore, the FortiGate device is a spoke that establishes dynamic IPsec tunnels to the hub. It also has the
network-overlay and auto-discovery-receiver options enabled, which means it can send ADVPN shortcut
requests to other spokes when it receives a shortcut offer from the hub


質問 # 44
Refer to the exhibit.

Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?

  • A. type must be set to static.
  • B. exchange-interface-ip must be enabled.
  • C. add-route must be disabled.
  • D. mode-cfg must be enabled.

正解:C


質問 # 45
Refer to the exhibit.

Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2. The administrator configured ADVPN on both hub-and-spoke groups.
Which two outcomes are expected if a user in Toronto sends traffic to London? (Choose two.)

  • A. London generates an IKE information message that contains the Toronto public IP address.
  • B. Traffic from Toronto to London triggers the dynamic negotiation of a direct site-to-site VPN.
  • C. The first packets from Toronto to London are routed through Hub 1 then to Hub 2.
  • D. Toronto needs to establish a site-to-site tunnel with Hub 2 to bypass Hub 1.

正解:B、C


質問 # 46
Refer to the exhibit.

The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate appliance that supports hardware offloading. Based on the information shown in the exhibits, which two statements about the session are true? (Choose two.)

  • A. The auxiliary session can be offloaded to hardware.
  • B. The original direction of the symmetric traffic flows from port3 to port2.
  • C. The reply direction of the asymmetric traffic flows from port2 to port3.
  • D. The main session cannot be offloaded to hardware.

正解:A、C


質問 # 47
......

Fortinet NSE7_SDW-7.2問題集で一発合格できる問題を試そう!:https://www.goshiken.com/Fortinet/NSE7_SDW-7.2-mondaishu.html

NSE7_SDW-7.2問題集を掴み取れ![最新2025]Fortinet試験問題を提供しています:https://drive.google.com/open?id=1i1t2S5QDHRitKl0fhCbEk4LmEo1yEHWw