無料Fortinet NSE7_SDW-7.0プレミアム試験エンジンPDFをダウンロード 更新された70問があります [Q39-Q64]

Share

無料Fortinet NSE7_SDW-7.0プレミアム試験エンジンPDFをダウンロード 更新された70問があります

検証済みNSE7_SDW-7.0リアル試験問題集PDF豪華お試しセット

質問 # 39
Refer to the exhibit.

FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN.
Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces? (Choose two.)

  • A. Use different proposals are used between the interfaces.
  • B. Configure the IKE mode to be aggressive mode.
  • C. Use unique Diffie Hellman groups on each VPN interface.
  • D. Specify a unique peer ID for each dial-up VPN interface.

正解:B、D


質問 # 40
Refer to the exhibits.

Exhibit A shows the packet duplication rule configuration, the SD-WAN zone status output, and the sniffer output on FortiGate acting as the sender. Exhibit B shows the sniffer output on a FortiGate acting as the receiver.
The administrator configured packet duplication on both FortiGate devices. The sniffer output on the sender FortiGate shows that FortiGate forwards an ICMP echo request packet over three overlays, but it only receives one reply packet through T_INET_1_0.
Based on the output shown in the exhibits, which two reasons can cause the observed behavior? (Choose two.)

  • A. On the sender FortiGate, duplication-max-num is set to 3.
  • B. On the receiver FortiGate, packet-de-duplication is enabled.
  • C. The ICMP echo request packets sent over T_INET_0_0 and T_MPLS_0 were dropped along the way.
  • D. The ICMP echo request packets received over T_INET_0_0 and T_MPLS_0 were offloaded to NPU.

正解:A、B


質問 # 41
Which two statements about SD-WAN central management are true? (Choose two.)

  • A. The objects are saved in the ADOM common object database.
  • B. It uses templates to configure SD-WAN on managed devices.
  • C. It supports normalized interfaces for SD-WAN member configuration.
  • D. It does not support meta fields.

正解:A、B

解説:
Explanation
Normalized interfaces are not supported for SD-WAN templates. You can create multiple SD-WAN zones and add interface members to the SD-WAN zones. You must bind the interface members by name to physical interfaces or VPN interfaces.https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan-new-features/794804/new-sd-wan-template-


質問 # 42
What is a benefit of using application steering in SD-WAN?

  • A. You steer traffic based on the detected application.
  • B. You do not need to configure firewall policies that accept the SD-WAN traffic.
  • C. The traffic always skips the regular policy routes.
  • D. You do not need to enable SSL inspection.

正解:A


質問 # 43
Refer to the exhibit.

Which statement about the role of the ADVPN device in handling traffic is true?

  • A. Two hubs, 10.0.1.101 and 10.0.2.101, are receiving and forwarding queries between each other.
  • B. Two spokes, 192.2.0.1 and 10.0.2.101, forward their queries to their hubs.
  • C. This is a spoke that has received a query from a remote hub and has forwarded the response to its hub.
  • D. This is a hub that has received a query from a spoke and has forwarded it to another spoke.

正解:D


質問 # 44
Refer to the exhibits.
Exhibit A

Exhibit B

Exhibit A shows the SD-WAN performance SLA configuration, the SD-WAN rule configuration, and the application IDs of Facebook and YouTube. Exhibit B shows the firewall policy configuration and the underlay zone status.
Based on the exhibits, which two statements are correct about the health and performance of port1 and port2? (Choose two.)

  • A. Non-TCP Facebook and YouTube traffic are not used for performance measurement.
  • B. FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.
  • C. The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.
  • D. FortiGate is unable to measure jitter and packet loss on Facebook and YouTube traffic.

正解:A、C

解説:
Study Guide 7.0, pages 88 - 89.
Study Guide 7.2, pages 103 - 104.
Another comment said "because without using application Control on the firewall policy, SDWAN can't work" but there is a app control "default" defined on config.


質問 # 45
Refer to the exhibit.

The device exchanges routes using IBGP.
Which two statements are correct about the IBGP configuration and routing information on the device?
(Choose two.)

  • A. ibgp-multipath is disabled.
  • B. You can run the get router info routing-table database command to display the additional paths.
  • C. Each BGP route is three hops away from the destination.
  • D. additional-path is enabled.

正解:B、D


質問 # 46
Refer to the exhibit.

Based on the exhibit, which statement about FortiGate re-evaluating traffic is true?

  • A. The type of traffic defined and allowed on firewall policy ID 1 is UDP.
  • B. Changes have been made on firewall policy ID 1 on FortiGate.
  • C. Firewall policy ID 1 has source NAT disabled.
  • D. FortiGate has terminated the session after a change on policy ID 1.

正解:B


質問 # 47
What are two reasons for using FortiManager to organize and manage the network for a group of FortiGate devices? (Choose two )

  • A. It sends probe signals as health checks to the beacon servers on behalf of FortiGate.
  • B. It simplifies the deployment and administration of SD-WAN on managed FortiGate devices.
  • C. It improves SD-WAN performance on the managed FortiGate devices.
  • D. It reduces WAN usage on FortiGate devices by acting as a local FortiGuard server.
  • E. It acts as a policy compliance entity to review all managed FortiGate devices.

正解:B、D


質問 # 48
Refer to the exhibit.

Which statement explains the output shown in the exhibit?

  • A. FortiGate used 192.2.0.1 as the gateway for the original direction of the traffic.
  • B. FortiGate will not re-evaluate the session following a firewall policy change.
  • C. FortiGate must re-evaluate the session due to routing change.
  • D. FortiGate performed standard FIB routing on the session.

正解:C


質問 # 49
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows a site-to-site topology between two FortiGate devices: branch1_fgt and dc1_fgt. Exhibit B shows the system global and system settings configuration on dc1_fgt.
When branch1_client establishes a connection to dc1_host, the administrator observes that, on dc1_fgt, the reply traffic is routed over T_INET_0_0, even though T_INET_1_0 is the preferredmember in the matching SD-WAN rule.
Based on the information shown in the exhibits, what configuration change must be made on dc1_fgt so dc1_fgt routes the reply traffic over T_INET_1_0?

  • A. Disable allow-subnet-overlap under config system settings.
  • B. Disable tp-session-without-syn under config system settings.
  • C. Enable snat-route-change under config system global.
  • D. Enable auxiliary-session under config system settings.

正解:D

解説:
Explanation
Controlling return path with auxiliary session When multiple incoming or outgoing interfaces are used in ECMP or for load balancing, changes to routing, incoming, or return traffic interfaces impacts how an existing sessions handles the traffic. Auxiliary sessions can be used to handle these changes to traffic patterns.https://docs.fortinet.com/document/fortigate/7.0.11/administration-guide/14295/controlling-return-path-


質問 # 50
Refer to the exhibits.

Which conclusion about the packet debug flow output is correct?

  • A. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
  • B. The packet size exceeded the outgoing interface MTU.
  • C. The total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
  • D. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the firewall policy, and the packet was dropped.

正解:A

解説:
In a Per-IP shaper configuration, if an IP address exceeds the configured concurrent session limit, the message "Denied by quota check" appears. SD-WAN 7.0 Study Guide page 287


質問 # 51
Refer to the exhibit.

The device exchanges routes using IBGP.
Which two statements are correct about the IBGP configuration and routing information on the device? (Choose two.)

  • A. ibgp-multipath is disabled.
  • B. You can run the get router info routing-table database command to display the additional paths.
  • C. Each BGP route is three hops away from the destination.
  • D. additional-path is enabled.

正解:B、D


質問 # 52
Which diagnostic command can you use to show the configured SD-WAN zones and their assigned members?

  • A. diagnose sys sdwan interface
  • B. diagnose sys sdwan member
  • C. diagnose sys sdwan service
  • D. diagnose sys sdwan zone

正解:D


質問 # 53
Which two tasks are part of using central VPN management? (Choose two.)

  • A. You configure VPN communities to define common IPsec settings shared by all VPN gateways.
  • B. You must enable VPN zones for SD-WAN deployments.
  • C. FortiManager installs VPN settings on both managed and external gateways.
  • D. You can configure full mesh, star, and dial-up VPN topologies.

正解:A、D


質問 # 54
Refer to the exhibit.

An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over T_INET_0_0. However, the traffic is routed over T_INET_1_0.
Based on the output shown in the exhibit, which two reasons can cause the observed behavior? (Choose two.)

  • A. T_INET_1_0 has a higher member configuration priority than T_INET_0_0.
  • B. The traffic matches a regular policy route configured with T_INET_1_0 as the outgoing device.
  • C. T_INET_1_0 has a lower route priority value (higher priority) than T_INET_0_0.
  • D. T_INET_0_0 does not have a valid route to the destination.

正解:B、D

解説:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Assigning-Priority-to-SD-WAN-Members-for-Default/ta-p/230911


質問 # 55
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SD-WAN member status, the routing table, and the performance SLA status.
If port2 is detected dead by FortiGate, what is the expected behavior?

  • A. FortiGate removes all static routes for port2.
  • B. Port2 becomes alive after three successful probes are detected.
  • C. The administrator manually restores the static routes for port2, if port2 becomes alive.
  • D. Host 8.8.8.8 is reachable through port1 and port2.

正解:A

解説:
Explanation
This is due to Update static route is enable which removes the static route entry referencing the interface if the interface is dead


質問 # 56
Which are three key routing principles in SD-WAN? (Choose three.)

  • A. SD-WAN rules have precedence over ISDB routes.
  • B. By default, SD-WAN members are skipped if they do not have a valid route to the destination.
  • C. FortiGate performs route lookups for new sessions only.
  • D. By default, SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.
  • E. Regular policy routes have precedence over SD-WAN rules.

正解:B、D、E


質問 # 57
Which two performance SLA protocols enable you to verify that the server response contains a specific value?
(Choose two.)

  • A. icmp
  • B. twamp
  • C. http
  • D. dns

正解:C、D


質問 # 58
Refer to the exhibit.

Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?

  • A. type must be set to static.
  • B. mode-cfg must be enabled.
  • C. add-route must be disabled.
  • D. exchange-interface-ip must be enabled.

正解:C

解説:
for using "non ike" routes (for example BGP/static and so on) you must do disable the add-route that inject automatically kernel route based on p2 selectors from the remote site from the SD-WAN_7.2_Study_Guide page 236


質問 # 59
Refer to the exhibit.

The exhibit shows the SD-WAN rule status and configuration.
Based on the exhibit, which change in the measured latency will make T_MPLS_0 the new preferred member?

  • A. When T_MPLS_0 has a latency of 100 ms.
  • B. When T_N1PLS_0 has a latency of 80 ms.
  • C. When T_INET_0_0 has a latency of 250 ms.
  • D. When T_INET_0_0 and T_MPLS_0 have the same latency.

正解:B


質問 # 60
Refer to the exhibits.


An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in exhibit A.
After generating GoToMeeting test traffic, the administrator examined the respective traffic log on FortiAnalyzer, which is shown in exhibit B.
The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.
Which two reasons explain why the traffic matched the implicit SD-WAN rule? (Choose two.)

  • A. FortiGate did not refresh the routing information on the session after the application was detected.
  • B. The session 3-tuple did not match any of the existing entries in the ISDB application cache.
  • C. Full SSL inspection is not enabled on the matching firewall policy.
  • D. Port1 and port2 do not have a valid route to the destination.

正解:A、C


質問 # 61
Refer to the exhibit.

Based on the output shown in the exhibit, which two criteria on the SD-WAN member configuration can be used to select an outgoing interface in an SD-WAN rule? (Choose two.)

  • A. Set load-balance-mode source-ip-ip-based.
  • B. Set cost 15.
  • C. Set priority 10.
  • D. Set source 100.64.1.1.

正解:B、C


質問 # 62
Which two performance SLA protocols enable you to verify that the server response contains a specific value? (Choose two.)

  • A. icmp
  • B. twamp
  • C. http
  • D. dns

正解:C、D

解説:
Pages 85,86 in Study guide 7.0 Pages 100,101 in Study guide 7


質問 # 63
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows the traffic shaping policy and exhibit B shows the firewall policy.
The administrator wants FortiGate to limit the bandwidth used by YouTube. When testing, the administrator determines that FortiGate does not apply traffic shaping on YouTube traffic.
Based on the policies shown in the exhibits, what configuration change must be made so FortiGate performs traffic shaping on YouTube traffic?

  • A. Destination internet service must be enabled on the traffic shaping policy.
  • B. Individual SD-WAN members must be selected as the outgoing interface on the traffic shaping policy.
  • C. Web filtering must be enabled on the firewall policy.
  • D. Application control must be enabled on the firewall policy.

正解:D


質問 # 64
......

あなたを合格させるFortinet試験にNSE7_SDW-7.0試験問題集:https://www.goshiken.com/Fortinet/NSE7_SDW-7.0-mondaishu.html

NSE7_SDW-7.0問題集PDF最新 [2023年最新] 究極の学習ガイド:https://drive.google.com/open?id=17R6fQf9P1cI8XtYzJtihin_Hin3tILMf