2024年最新のFortinet NSE7_SDW-7.2試験問題には85問があります [Q39-Q60]

Share

2024年最新のFortinet NSE7_SDW-7.2試験問題には85問があります

無料で使えるNSE7_SDW-7.2別格な問題集をダウンロード2024年08月14日に更新された85問があります

質問 # 39
Refer to the exhibit.

Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to
exchange routes over IPsec?

  • A. exchange-interface-ip must be enabled.
  • B. type must be set to static.
  • C. add-route must be disabled.
  • D. mode-cfg must be enabled.

正解:C


質問 # 40
Exhibit.

The exhibit shows the output of the command diagnose sys sdwan health-check status collected on a FortiGate device. Which two statements are correct about the health check status on this FortiGate device? (Choose two.)

  • A. The health-check VPN_PING orders the members according to the lowest jitter.
  • B. The interface T_INET_1 missed one SLA target.
  • C. The interface T_INET_0 missed three SLA targets.
  • D. There is no SLA criteria configured for the health-check Level3_DNS.

正解:A、D

解説:
According to the FortiGate / FortiOS 6.4.2 Administration Guide, the health check status command displays the status of the health check probes for each SD-WAN member interface. The output includes the following information:
state: the current state of the interface, either alive or dead
packet-loss: the percentage of packets lost during the health check
latency: the average round-trip time in milliseconds
jitter: the variation in latency
mos: the mean opinion score, a measure of voice quality
bandwidth: the available bandwidth in kilobits per second for each direction (up, down, bi) sla map: a bitmap that indicates which SLA criteria are met or failed Based on the exhibit, the following statements are correct:
The health-check VPN_PING orders the members according to the lowest jitter. This means that the interface with the lowest jitter value is listed first, followed by the next lowest, and so on1. In the exhibit, the order is T_MPLS, T_INET_1, and T_INET_0.
There is no SLA criteria configured for the health-check Level3_DNS. This means that the health check does not use any SLA parameters to determine the state of the interface2. In the exhibit, the sla map value is 0x0 for both port1 and port2, indicating that no SLA criteria are applied.


質問 # 41
Refer to the exhibit.

Based on the output, which two conclusions are true? (Choose two.)

  • A. There is more than one SD-WAN rule configured.
  • B. The SD-WAN rules take precedence over regular policy routes.
  • C. The all_rules rule represents the implicit SD-WAN rule.
  • D. Entry 1(id=1) is a regular policy route.

正解:A、D


質問 # 42
Refer to the exhibit.

In a dual-hub hub-and-spoke SD-WAN deployment, which is a benefit of disabling the anti-replay setting on the hubs?

  • A. It instructs the hub to skip content inspection on TCP traffic, to improve performance.
  • B. It instructs the hub to disable the reordering of TCP packets on behalf of the receiver, to improve performance.
  • C. It instructs the hub to not check the ESP sequence numbers on IPsec traffic, to improve performance.
  • D. It instructs the hub to disable TCP sequence number check, which is required for TCP sessions originated from spokes to fail over back and forth between the hubs.

正解:D


質問 # 43
Refer to the exhibit, which shows an SD-WAN zone configuration on the FortiGate GUI.

Based on the exhibit, which statement is true?

  • A. The overlay zone contains four members.
  • B. You can delete the virtual-wan-link zone because it contains no member.
  • C. The corporate zone contains no member.
  • D. You can move port1 from the underlay zone to the overlay zone.

正解:C

解説:
Based on the exhibit, the "corporate" zone contains no member (B). In the FortiGate GUI, zones without members do not display any interfaces listed under them, which is the case for the corporate zone in the exhibit. Reference: This conclusion is based on standard Fortinet GUI interpretation and the operational logic of SD-WAN zones as per Fortinet's guidelines and user interface standards.


質問 # 44
Which three matching traffic criteria are available in SD-WAN rules? (Choose three.)

  • A. Application signatures
  • B. URL categories
  • C. Internet service database (ISDB) address object
  • D. Type of physical link connection
  • E. Source and destination IP address

正解:A、C、D


質問 # 45
Refer to the exhibit.

The exhibit shows the SD-WAN rule status and configuration.
Based on the exhibit, which change in the measured latency will make T_MPLS_0 the new preferred member?

  • A. When T_N1PLS_0 has a latency of 80 ms.
  • B. When T_MPLS_0 has a latency of 100 ms.
  • C. When T_INET_0_0 has a latency of 250 ms.
  • D. When T_INET_0_0 and T_MPLS_0 have the same latency.

正解:A


質問 # 46
Which two statements are true about using SD-WAN to steer local-out traffic? (Choose two.)

  • A. FortiGate does not consider the source address of the packet when matching an SD-WAN rule for
    local-out traffic.
  • B. By default, local-out traffic does not use SD-WAN.
  • C. You must configure each local-out feature individually, to use SD-WAN.
  • D. By default, FortiGate does not check if the selected member has a valid route to the destination.

正解:B、C


質問 # 47
Refer to the exhibit.

Based on the exhibit, which two actions does FortiGate perform on sessions after a firewall policy change? (Choose two.)

  • A. FortiGate flushes all sessions.
  • B. FortiGate terminates the old sessions.
  • C. FortiGate evaluates new sessions.
  • D. FortiGate does not change existing sessions.

正解:C、D

解説:
FortiGate not to flag existing impacted session as dirty by setting firewall-session-dirty to check new. The results is that FortiGate evaluates only new session against the new firewall policy.


質問 # 48
Which two statements about SD-WAN central management are true? (Choose two.)

  • A. It does not support meta fields.
  • B. It supports normalized interfaces for SD-WAN member configuration.
  • C. The objects are saved in the ADOM common object database.
  • D. It uses templates to configure SD-WAN on managed devices.

正解:C、D

解説:
Normalized interfaces are not supported for SD-WAN templates. You can create multiple SD-WAN zones and add interface members to the SD-WAN zones. You must bind the interface members by name to physical interfaces or VPN interfaces.https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan-new-features/794804/new-sd-wan-template-fmg


質問 # 49
Refer to the exhibit.

Which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules?

  • A. All traffic from a source IP is sent to the same interface.
  • B. All traffic from a source IP to a destination IP is sent to the least used interface.
  • C. All traffic from a source IP is sent to the most used interface.
  • D. All traffic from a source IP to a destination IP is sent to the same interface.

正解:D

解説:
Explanation
Study Guide 7.2, page 176.


質問 # 50
Refer to the exhibits.

Exhibit A shows the packet duplication rule configuration, the SD-WAN zone status output, and the sniffer output on FortiGate acting as the sender. Exhibit B shows the sniffer output on a FortiGate acting as the receiver.
The administrator configured packet duplication on both FortiGate devices. The sniffer output on the sender FortiGate shows that FortiGate forwards an ICMP echo request packet over three overlays, but it only receives one reply packet through T_INET_1_0.
Based on the output shown in the exhibits, which two reasons can cause the observed behavior? (Choose two.)

  • A. The ICMP echo request packets sent over T_INET_0_0 and T_MPLS_0 were dropped along the way.
  • B. On the sender FortiGate, duplication-max-num is set to 3.
  • C. On the receiver FortiGate, packet-de-duplication is enabled.
  • D. The ICMP echo request packets received over T_INET_0_0 and T_MPLS_0 were offloaded to NPU.

正解:B、C


質問 # 51
Refer to the exhibit.

In a dual-hub hub-and-spoke SD-WAN deployment, which is a benefit of disabling the anti-replay setting on the hubs?

  • A. It instructs the hub to skip content inspection on TCP traffic, to improve performance.
  • B. It instructs the hub to disable the reordering of TCP packets on behalf of the receiver, to improve performance.
  • C. It instructs the hub to not check the ESP sequence numbers on IPsec traffic, to improve performance.
  • D. It instructs the hub to disable TCP sequence number check, which is required for TCP sessions originated from spokes to fail over back and forth between the hubs.

正解:D


質問 # 52
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows the traffic shaping policy and exhibit B shows the firewall policy.
The administrator wants FortiGate to limit the bandwidth used by YouTube. When testing, the administrator
determines that FortiGate does not apply traffic shaping on YouTube traffic.
Based on the policies shown in the exhibits, what configuration change must be made so FortiGate performs
traffic shaping on YouTube traffic?

  • A. Destination internet service must be enabled on the traffic shaping policy.
  • B. Individual SD-WAN members must be selected as the outgoing interface on the traffic shaping policy.
  • C. Application control must be enabled on the firewall policy.
  • D. Web filtering must be enabled on the firewall policy.

正解:C


質問 # 53
Refer to the exhibit.

The device exchanges routes using IBGP.
Which two statements are correct about the IBGP configuration and routing information on the device?
(Choose two.)

  • A. Each BGP route is three hops away from the destination.
  • B. ibgp-multipath is disabled.
  • C. additional-path is enabled.
  • D. You can run the get router info routing-table database command to display the additional paths.

正解:C、D


質問 # 54
Which two statements about SD-WAN central management are true? (Choose two.)

  • A. It does not support meta fields.
  • B. It supports normalized interfaces for SD-WAN member configuration.
  • C. The objects are saved in the ADOM common object database.
  • D. It uses templates to configure SD-WAN on managed devices.

正解:C、D

解説:
Explanation
Normalized interfaces are not supported for SD-WAN templates. You can create multiple SD-WAN zones and
add interface members to the SD-WAN zones. You must bind the interface members by name to physical
interfaces or VPN
interfaces.https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan-new-features/794804/new-sd-wan-template-


質問 # 55
Refer to the exhibits.


An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator
collected the information shown in exhibit A.
After generating GoToMeeting test traffic, the administrator examined the respective traffic log on
FortiAnalyzer, which is shown in exhibit B. The administrator noticed that the traffic matched the implicit
SD-WAN rule, but they expected the traffic to match rule ID 1.
Which two reasons explain why the traffic matched the implicit SD-WAN rule? (Choose two.)

  • A. FortiGate did not refresh the routing information on the session after the application was detected.
  • B. The session 3-tuple did not match any of the existing entries in the ISDB application cache.
  • C. Full SSL inspection is not enabled on the matching firewall policy.
  • D. Port1 and port2 do not have a valid route to the destination.

正解:A、B

解説:
Explanation
Study guide 7.2 Page 191


質問 # 56
Refer to the exhibits.


An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in exhibit A.
After generating GoToMeeting test traffic, the administrator examined the respective traffic log on FortiAnalyzer, which is shown in exhibit B.
The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.
Which two reasons explain why the traffic matched the implicit SD-WAN rule? (Choose two.)

  • A. FortiGate did not refresh the routing information on the session after the application was detected.
  • B. The session 3-tuple did not match any of the existing entries in the ISDB application cache.
  • C. Full SSL inspection is not enabled on the matching firewall policy.
  • D. Port1 and port2 do not have a valid route to the destination.

正解:A、B

解説:
Study guide 7.2 Page 191


質問 # 57
Refer to the exhibit.

The exhibit shows the SD-WAN rule status and configuration.
Based on the exhibit, which change in the measured latency will make T_MPLS_0 the new preferred member?

  • A. When T_N1PLS_0 has a latency of 80 ms.
  • B. When T_MPLS_0 has a latency of 100 ms.
  • C. When T_INET_0_0 has a latency of 250 ms.
  • D. When T_INET_0_0 and T_MPLS_0 have the same latency.

正解:A


質問 # 58
Which two interfaces are considered overlay links? (Choose two.)

  • A. Physical
  • B. GRE
  • C. LAG
  • D. IPsec

正解:C


質問 # 59
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows a site-to-site topology between two FortiGate devices: branch1_fgt and dc1_fgt. Exhibit B shows the system global and system settings configuration on dc1_fgt.
When branch1_client establishes a connection to dc1_host, the administrator observes that, on dc1_fgt, the reply traffic is routed over T_INET_0_0, even though T_INET_1_0 is the preferred member in the matching SD-WAN rule.
Based on the information shown in the exhibits, what configuration change must be made on dc1_fgt so dc1_fgt routes the reply traffic over T_INET_1_0?

  • A. Disable tcp-session-without-syn under config system settings.
  • B. Enable auxiliary-session under config system settings.
  • C. Enable snat-route-change under config system global.
  • D. Disable allow-subnet-overlap under config system settings.

正解:A


質問 # 60
......

Fortinet NSE7_SDW-7.2試験実践テスト問題:https://www.goshiken.com/Fortinet/NSE7_SDW-7.2-mondaishu.html

最新の認定試験NSE7_SDW-7.2問題集-実践テスト問題:https://drive.google.com/open?id=1H7bX3-yrI1xR1Bl-ZtjWxs3kdRGTg5RS