Fortinet FortiOS 7.6 NSE4_FGT_AD-7.6 Secure SD WAN Concepts Routing Behavior SLA Quality Practice Test

 

This Fortinet NSE4_FGT_AD-7.6 practice test focuses on secure sd wan concepts routing behavior sla quality and link use through original applied scenarios aligned to the current Fortinet NSE 4 – FortiOS 7.6 Administrator scope for FortiOS 7.6.0. Use the full ExamSnap NSE4_FGT_AD-7.6 collection for broader practice across all current domains. For broader exam preparation, review the Fortinet NSE4_FGT_AD-7.6 Exam Dumps page.

Question 1

At City Power & Light, a infrastructure engineer is handling a FortiGate 7.6 change. The requirement is to treat several WAN transports as a logical policy-controlled egress. What should the administrator do? The team wants the smallest change that directly addresses the requirement.

  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design
  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Probe a target that represents the real service path rather than only the first-hop gateway
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability

Correct answer: B

Explanation

  1. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to treat several WAN transports as a logical policy-controlled egress.
  2. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules. This directly satisfies the stated requirement.
  3. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to treat several WAN transports as a logical policy-controlled egress.
  4. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to treat several WAN transports as a logical policy-controlled egress.
  5. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to treat several WAN transports as a logical policy-controlled egress.

Learning point: For this FortiOS 7.6 scenario, add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules.

Question 2

During a maintenance window at Margie Travel, the team must prefer a high-quality link for latency-sensitive applications while retaining another link for resilience. Which action is the most appropriate? The choice should follow normal FortiOS administration practice.

  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Use SD-WAN rules with application or traffic matching and a strategy that considers measured link quality
  • Use an SLA-aware lowest-cost strategy with correct member cost and health checks
  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Probe a target that represents the real service path rather than only the first-hop gateway

Correct answer: B

Explanation

  1. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer a high-quality link for latency-sensitive applications while retaining another link for resilience.
  2. SD-WAN can select links per traffic class and measured health instead of using a single static default path. This directly satisfies the stated requirement.
  3. An SLA-aware cost strategy can prefer an inexpensive healthy path and move traffic when that path is no longer acceptable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer a high-quality link for latency-sensitive applications while retaining another link for resilience.
  4. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer a high-quality link for latency-sensitive applications while retaining another link for resilience.
  5. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer a high-quality link for latency-sensitive applications while retaining another link for resilience.

Learning point: For this FortiOS 7.6 scenario, use SD-WAN rules with application or traffic matching and a strategy that considers measured link quality. SD-WAN can select links per traffic class and measured health instead of using a single static default path.

Question 3

A change review at Bellows College identifies one requirement: measure whether a WAN member meets latency, jitter, and packet-loss requirements. Which FortiGate action best satisfies it? The solution must preserve the existing production design where possible.

  • Add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design
  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Configure a Performance SLA health check toward a representative reachable target
  • Account for the implicit SD-WAN rule and its configured or default member-selection behavior
  • Reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules

Correct answer: C

Explanation

  1. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure whether a WAN member meets latency, jitter, and packet-loss requirements.
  2. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure whether a WAN member meets latency, jitter, and packet-loss requirements.
  3. Performance SLA probes measure member health and quality for SD-WAN decisions. This directly satisfies the stated requirement.
  4. Unmatched SD-WAN traffic is handled by the implicit rule after explicit rules are evaluated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure whether a WAN member meets latency, jitter, and packet-loss requirements.
  5. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure whether a WAN member meets latency, jitter, and packet-loss requirements.

Learning point: For this FortiOS 7.6 scenario, configure a Performance SLA health check toward a representative reachable target. Performance SLA probes measure member health and quality for SD-WAN decisions.

Question 4

While troubleshooting at Adventure Works, the security engineer needs to avoid declaring an internet link healthy when only the directly connected gateway is reachable. What is the best next step? The change is being made during a controlled production window.

  • Use an SLA-aware lowest-cost strategy with correct member cost and health checks
  • Configure a Performance SLA health check toward a representative reachable target
  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Probe a target that represents the real service path rather than only the first-hop gateway
  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path

Correct answer: D

Explanation

  1. An SLA-aware cost strategy can prefer an inexpensive healthy path and move traffic when that path is no longer acceptable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid declaring an internet link healthy when only the directly connected gateway is reachable.
  2. Performance SLA probes measure member health and quality for SD-WAN decisions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid declaring an internet link healthy when only the directly connected gateway is reachable.
  3. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid declaring an internet link healthy when only the directly connected gateway is reachable.
  4. A representative health-check target gives a better indication of end-to-end path usability. This directly satisfies the stated requirement.
  5. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid declaring an internet link healthy when only the directly connected gateway is reachable.

Learning point: For this FortiOS 7.6 scenario, probe a target that represents the real service path rather than only the first-hop gateway. A representative health-check target gives a better indication of end-to-end path usability.

Question 5

Fourth Coffee is standardizing its FortiGate 7.6 operations. Which approach should it use to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone? The team will validate the result immediately after the change.

  • Probe a target that represents the real service path rather than only the first-hop gateway
  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design
  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability

Correct answer: D

Explanation

  1. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone.
  2. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone.
  3. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone.
  4. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This directly satisfies the stated requirement.
  5. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone.

Learning point: For this FortiOS 7.6 scenario, add or correct the route that makes the destination reachable through the SD-WAN zone or member path. SD-WAN rules influence member selection but do not eliminate the need for valid routing.

Question 6

A production ticket for Consolidated Messenger states that administrators must understand what happens when no explicit SD-WAN service rule matches. Which choice is correct? No unrelated security controls should be changed.

  • Probe a target that represents the real service path rather than only the first-hop gateway
  • Account for the implicit SD-WAN rule and its configured or default member-selection behavior
  • Reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules
  • Use SD-WAN rules with application or traffic matching and a strategy that considers measured link quality
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability

Correct answer: B

Explanation

  1. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand what happens when no explicit SD-WAN service rule matches.
  2. Unmatched SD-WAN traffic is handled by the implicit rule after explicit rules are evaluated. This directly satisfies the stated requirement.
  3. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand what happens when no explicit SD-WAN service rule matches.
  4. SD-WAN can select links per traffic class and measured health instead of using a single static default path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand what happens when no explicit SD-WAN service rule matches.
  5. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand what happens when no explicit SD-WAN service rule matches.

Learning point: For this FortiOS 7.6 scenario, account for the implicit SD-WAN rule and its configured or default member-selection behavior. Unmatched SD-WAN traffic is handled by the implicit rule after explicit rules are evaluated.

Question 7

The security team at VanArsdel wants to remove a link from quality-sensitive selection when it exceeds the configured SLA thresholds. Which FortiGate configuration or action most directly meets that goal? The administrator wants a configuration that is easy to audit later.

  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability
  • Configure a Performance SLA health check toward a representative reachable target
  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Account for the implicit SD-WAN rule and its configured or default member-selection behavior

Correct answer: D

Explanation

  1. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to remove a link from quality-sensitive selection when it exceeds the configured SLA thresholds.
  2. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to remove a link from quality-sensitive selection when it exceeds the configured SLA thresholds.
  3. Performance SLA probes measure member health and quality for SD-WAN decisions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to remove a link from quality-sensitive selection when it exceeds the configured SLA thresholds.
  4. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This directly satisfies the stated requirement.
  5. Unmatched SD-WAN traffic is handled by the implicit rule after explicit rules are evaluated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to remove a link from quality-sensitive selection when it exceeds the configured SLA thresholds.

Learning point: For this FortiOS 7.6 scenario, use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds.

Question 8

An incident at Northwind Health requires the security engineer to troubleshoot why a member is not selected despite being physically up. What should be done first? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.

  • Reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules
  • Use SD-WAN rules with application or traffic matching and a strategy that considers measured link quality
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability
  • Probe a target that represents the real service path rather than only the first-hop gateway
  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy

Correct answer: C

Explanation

  1. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot why a member is not selected despite being physically up.
  2. SD-WAN can select links per traffic class and measured health instead of using a single static default path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot why a member is not selected despite being physically up.
  3. Physical link state alone does not determine SD-WAN selection. This directly satisfies the stated requirement.
  4. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot why a member is not selected despite being physically up.
  5. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot why a member is not selected despite being physically up.

Learning point: For this FortiOS 7.6 scenario, check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability. Physical link state alone does not determine SD-WAN selection.

Question 9

For a FortiGate 7.6 deployment at Blue Yonder Airlines, which option correctly addresses the need to send ordinary traffic over the lowest-cost healthy link and fail over when it stops meeting the SLA? The team wants the smallest change that directly addresses the requirement.

  • Add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design
  • Account for the implicit SD-WAN rule and its configured or default member-selection behavior
  • Use SD-WAN rules with application or traffic matching and a strategy that considers measured link quality
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability
  • Use an SLA-aware lowest-cost strategy with correct member cost and health checks

Correct answer: E

Explanation

  1. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send ordinary traffic over the lowest-cost healthy link and fail over when it stops meeting the SLA.
  2. Unmatched SD-WAN traffic is handled by the implicit rule after explicit rules are evaluated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send ordinary traffic over the lowest-cost healthy link and fail over when it stops meeting the SLA.
  3. SD-WAN can select links per traffic class and measured health instead of using a single static default path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send ordinary traffic over the lowest-cost healthy link and fail over when it stops meeting the SLA.
  4. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send ordinary traffic over the lowest-cost healthy link and fail over when it stops meeting the SLA.
  5. An SLA-aware cost strategy can prefer an inexpensive healthy path and move traffic when that path is no longer acceptable. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, use an SLA-aware lowest-cost strategy with correct member cost and health checks. An SLA-aware cost strategy can prefer an inexpensive healthy path and move traffic when that path is no longer acceptable.

Question 10

Trey Research has validated routing and basic reachability. The remaining requirement is to direct business traffic to one zone without hard-coding a physical interface into every firewall rule. Which action should the team take? The choice should follow normal FortiOS administration practice.

  • Account for the implicit SD-WAN rule and its configured or default member-selection behavior
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability
  • Reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules
  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Use an SLA-aware lowest-cost strategy with correct member cost and health checks

Correct answer: C

Explanation

  1. Unmatched SD-WAN traffic is handled by the implicit rule after explicit rules are evaluated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to direct business traffic to one zone without hard-coding a physical interface into every firewall rule.
  2. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to direct business traffic to one zone without hard-coding a physical interface into every firewall rule.
  3. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection. This directly satisfies the stated requirement.
  4. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to direct business traffic to one zone without hard-coding a physical interface into every firewall rule.
  5. An SLA-aware cost strategy can prefer an inexpensive healthy path and move traffic when that path is no longer acceptable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to direct business traffic to one zone without hard-coding a physical interface into every firewall rule.

Learning point: For this FortiOS 7.6 scenario, reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection.

Question 11

At Nod Publishers, a infrastructure engineer is handling a FortiGate 7.6 change. The requirement is to treat several WAN transports as a logical policy-controlled egress. What should the administrator do? The solution must preserve the existing production design where possible.

  • Account for the implicit SD-WAN rule and its configured or default member-selection behavior
  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability
  • Add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design
  • Probe a target that represents the real service path rather than only the first-hop gateway

Correct answer: D

Explanation

  1. Unmatched SD-WAN traffic is handled by the implicit rule after explicit rules are evaluated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to treat several WAN transports as a logical policy-controlled egress.
  2. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to treat several WAN transports as a logical policy-controlled egress.
  3. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to treat several WAN transports as a logical policy-controlled egress.
  4. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules. This directly satisfies the stated requirement.
  5. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to treat several WAN transports as a logical policy-controlled egress.

Learning point: For this FortiOS 7.6 scenario, add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules.

Question 12

During a maintenance window at Contoso Finance, the team must prefer a high-quality link for latency-sensitive applications while retaining another link for resilience. Which action is the most appropriate? The change is being made during a controlled production window.

  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Use SD-WAN rules with application or traffic matching and a strategy that considers measured link quality
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability
  • Add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design

Correct answer: C

Explanation

  1. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer a high-quality link for latency-sensitive applications while retaining another link for resilience.
  2. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer a high-quality link for latency-sensitive applications while retaining another link for resilience.
  3. SD-WAN can select links per traffic class and measured health instead of using a single static default path. This directly satisfies the stated requirement.
  4. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer a high-quality link for latency-sensitive applications while retaining another link for resilience.
  5. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer a high-quality link for latency-sensitive applications while retaining another link for resilience.

Learning point: For this FortiOS 7.6 scenario, use SD-WAN rules with application or traffic matching and a strategy that considers measured link quality. SD-WAN can select links per traffic class and measured health instead of using a single static default path.

Question 13

A change review at Litware Logistics identifies one requirement: measure whether a WAN member meets latency, jitter, and packet-loss requirements. Which FortiGate action best satisfies it? The team will validate the result immediately after the change.

  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability
  • Use an SLA-aware lowest-cost strategy with correct member cost and health checks
  • Add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design
  • Configure a Performance SLA health check toward a representative reachable target

Correct answer: E

Explanation

  1. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure whether a WAN member meets latency, jitter, and packet-loss requirements.
  2. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure whether a WAN member meets latency, jitter, and packet-loss requirements.
  3. An SLA-aware cost strategy can prefer an inexpensive healthy path and move traffic when that path is no longer acceptable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure whether a WAN member meets latency, jitter, and packet-loss requirements.
  4. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure whether a WAN member meets latency, jitter, and packet-loss requirements.
  5. Performance SLA probes measure member health and quality for SD-WAN decisions. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, configure a Performance SLA health check toward a representative reachable target. Performance SLA probes measure member health and quality for SD-WAN decisions.

Question 14

While troubleshooting at Wide World Importers, the security engineer needs to avoid declaring an internet link healthy when only the directly connected gateway is reachable. What is the best next step? No unrelated security controls should be changed.

  • Use an SLA-aware lowest-cost strategy with correct member cost and health checks
  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Probe a target that represents the real service path rather than only the first-hop gateway
  • Configure a Performance SLA health check toward a representative reachable target
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability

Correct answer: C

Explanation

  1. An SLA-aware cost strategy can prefer an inexpensive healthy path and move traffic when that path is no longer acceptable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid declaring an internet link healthy when only the directly connected gateway is reachable.
  2. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid declaring an internet link healthy when only the directly connected gateway is reachable.
  3. A representative health-check target gives a better indication of end-to-end path usability. This directly satisfies the stated requirement.
  4. Performance SLA probes measure member health and quality for SD-WAN decisions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid declaring an internet link healthy when only the directly connected gateway is reachable.
  5. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid declaring an internet link healthy when only the directly connected gateway is reachable.

Learning point: For this FortiOS 7.6 scenario, probe a target that represents the real service path rather than only the first-hop gateway. A representative health-check target gives a better indication of end-to-end path usability.

Question 15

Graphic Design Institute is standardizing its FortiGate 7.6 operations. Which approach should it use to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone? The administrator wants a configuration that is easy to audit later.

  • Probe a target that represents the real service path rather than only the first-hop gateway
  • Use an SLA-aware lowest-cost strategy with correct member cost and health checks
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability
  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Account for the implicit SD-WAN rule and its configured or default member-selection behavior

Correct answer: D

Explanation

  1. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone.
  2. An SLA-aware cost strategy can prefer an inexpensive healthy path and move traffic when that path is no longer acceptable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone.
  3. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone.
  4. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This directly satisfies the stated requirement.
  5. Unmatched SD-WAN traffic is handled by the implicit rule after explicit rules are evaluated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone.

Learning point: For this FortiOS 7.6 scenario, add or correct the route that makes the destination reachable through the SD-WAN zone or member path. SD-WAN rules influence member selection but do not eliminate the need for valid routing.

Question 16

A production ticket for Lamna Healthcare states that administrators must understand what happens when no explicit SD-WAN service rule matches. Which choice is correct? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.

  • Add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design
  • Account for the implicit SD-WAN rule and its configured or default member-selection behavior
  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Configure a Performance SLA health check toward a representative reachable target
  • Probe a target that represents the real service path rather than only the first-hop gateway

Correct answer: B

Explanation

  1. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand what happens when no explicit SD-WAN service rule matches.
  2. Unmatched SD-WAN traffic is handled by the implicit rule after explicit rules are evaluated. This directly satisfies the stated requirement.
  3. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand what happens when no explicit SD-WAN service rule matches.
  4. Performance SLA probes measure member health and quality for SD-WAN decisions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand what happens when no explicit SD-WAN service rule matches.
  5. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand what happens when no explicit SD-WAN service rule matches.

Learning point: For this FortiOS 7.6 scenario, account for the implicit SD-WAN rule and its configured or default member-selection behavior. Unmatched SD-WAN traffic is handled by the implicit rule after explicit rules are evaluated.

Question 17

The security team at Tailspin Toys wants to remove a link from quality-sensitive selection when it exceeds the configured SLA thresholds. Which FortiGate configuration or action most directly meets that goal? The team wants the smallest change that directly addresses the requirement.

  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Use SD-WAN rules with application or traffic matching and a strategy that considers measured link quality
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability
  • Reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules
  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy

Correct answer: E

Explanation

  1. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to remove a link from quality-sensitive selection when it exceeds the configured SLA thresholds.
  2. SD-WAN can select links per traffic class and measured health instead of using a single static default path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to remove a link from quality-sensitive selection when it exceeds the configured SLA thresholds.
  3. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to remove a link from quality-sensitive selection when it exceeds the configured SLA thresholds.
  4. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to remove a link from quality-sensitive selection when it exceeds the configured SLA thresholds.
  5. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds.

Question 18

An incident at Humongous Insurance requires the security engineer to troubleshoot why a member is not selected despite being physically up. What should be done first? The choice should follow normal FortiOS administration practice.

  • Reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules
  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Use an SLA-aware lowest-cost strategy with correct member cost and health checks
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability
  • Probe a target that represents the real service path rather than only the first-hop gateway

Correct answer: D

Explanation

  1. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot why a member is not selected despite being physically up.
  2. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot why a member is not selected despite being physically up.
  3. An SLA-aware cost strategy can prefer an inexpensive healthy path and move traffic when that path is no longer acceptable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot why a member is not selected despite being physically up.
  4. Physical link state alone does not determine SD-WAN selection. This directly satisfies the stated requirement.
  5. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot why a member is not selected despite being physically up.

Learning point: For this FortiOS 7.6 scenario, check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability. Physical link state alone does not determine SD-WAN selection.

Question 19

For a FortiGate 7.6 deployment at Coho Winery, which option correctly addresses the need to send ordinary traffic over the lowest-cost healthy link and fail over when it stops meeting the SLA? The solution must preserve the existing production design where possible.

  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Use an SLA-aware lowest-cost strategy with correct member cost and health checks
  • Add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability
  • Probe a target that represents the real service path rather than only the first-hop gateway

Correct answer: B

Explanation

  1. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send ordinary traffic over the lowest-cost healthy link and fail over when it stops meeting the SLA.
  2. An SLA-aware cost strategy can prefer an inexpensive healthy path and move traffic when that path is no longer acceptable. This directly satisfies the stated requirement.
  3. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send ordinary traffic over the lowest-cost healthy link and fail over when it stops meeting the SLA.
  4. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send ordinary traffic over the lowest-cost healthy link and fail over when it stops meeting the SLA.
  5. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send ordinary traffic over the lowest-cost healthy link and fail over when it stops meeting the SLA.

Learning point: For this FortiOS 7.6 scenario, use an SLA-aware lowest-cost strategy with correct member cost and health checks. An SLA-aware cost strategy can prefer an inexpensive healthy path and move traffic when that path is no longer acceptable.

Question 20

Relecloud has validated routing and basic reachability. The remaining requirement is to direct business traffic to one zone without hard-coding a physical interface into every firewall rule. Which action should the team take? The change is being made during a controlled production window.

  • Account for the implicit SD-WAN rule and its configured or default member-selection behavior
  • Reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules
  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Probe a target that represents the real service path rather than only the first-hop gateway

Correct answer: B

Explanation

  1. Unmatched SD-WAN traffic is handled by the implicit rule after explicit rules are evaluated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to direct business traffic to one zone without hard-coding a physical interface into every firewall rule.
  2. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection. This directly satisfies the stated requirement.
  3. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to direct business traffic to one zone without hard-coding a physical interface into every firewall rule.
  4. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to direct business traffic to one zone without hard-coding a physical interface into every firewall rule.
  5. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to direct business traffic to one zone without hard-coding a physical interface into every firewall rule.

Learning point: For this FortiOS 7.6 scenario, reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection.

Question 21

At Woodgrove Bank, a infrastructure engineer is handling a FortiGate 7.6 change. The requirement is to treat several WAN transports as a logical policy-controlled egress. What should the administrator do? The team will validate the result immediately after the change.

  • Reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules
  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design
  • Configure a Performance SLA health check toward a representative reachable target
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability

Correct answer: C

Explanation

  1. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to treat several WAN transports as a logical policy-controlled egress.
  2. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to treat several WAN transports as a logical policy-controlled egress.
  3. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules. This directly satisfies the stated requirement.
  4. Performance SLA probes measure member health and quality for SD-WAN decisions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to treat several WAN transports as a logical policy-controlled egress.
  5. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to treat several WAN transports as a logical policy-controlled egress.

Learning point: For this FortiOS 7.6 scenario, add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules.

Question 22

During a maintenance window at Alpine Ski House, the team must prefer a high-quality link for latency-sensitive applications while retaining another link for resilience. Which action is the most appropriate? No unrelated security controls should be changed.

  • Probe a target that represents the real service path rather than only the first-hop gateway
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability
  • Configure a Performance SLA health check toward a representative reachable target
  • Add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design
  • Use SD-WAN rules with application or traffic matching and a strategy that considers measured link quality

Correct answer: E

Explanation

  1. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer a high-quality link for latency-sensitive applications while retaining another link for resilience.
  2. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer a high-quality link for latency-sensitive applications while retaining another link for resilience.
  3. Performance SLA probes measure member health and quality for SD-WAN decisions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer a high-quality link for latency-sensitive applications while retaining another link for resilience.
  4. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer a high-quality link for latency-sensitive applications while retaining another link for resilience.
  5. SD-WAN can select links per traffic class and measured health instead of using a single static default path. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, use SD-WAN rules with application or traffic matching and a strategy that considers measured link quality. SD-WAN can select links per traffic class and measured health instead of using a single static default path.

Question 23

A change review at Datum Corporation identifies one requirement: measure whether a WAN member meets latency, jitter, and packet-loss requirements. Which FortiGate action best satisfies it? The administrator wants a configuration that is easy to audit later.

  • Configure a Performance SLA health check toward a representative reachable target
  • Probe a target that represents the real service path rather than only the first-hop gateway
  • Account for the implicit SD-WAN rule and its configured or default member-selection behavior
  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability

Correct answer: A

Explanation

  1. Performance SLA probes measure member health and quality for SD-WAN decisions. This directly satisfies the stated requirement.
  2. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure whether a WAN member meets latency, jitter, and packet-loss requirements.
  3. Unmatched SD-WAN traffic is handled by the implicit rule after explicit rules are evaluated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure whether a WAN member meets latency, jitter, and packet-loss requirements.
  4. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure whether a WAN member meets latency, jitter, and packet-loss requirements.
  5. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure whether a WAN member meets latency, jitter, and packet-loss requirements.

Learning point: For this FortiOS 7.6 scenario, configure a Performance SLA health check toward a representative reachable target. Performance SLA probes measure member health and quality for SD-WAN decisions.

Question 24

While troubleshooting at Southridge Video, the security engineer needs to avoid declaring an internet link healthy when only the directly connected gateway is reachable. What is the best next step? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.

  • Configure a Performance SLA health check toward a representative reachable target
  • Probe a target that represents the real service path rather than only the first-hop gateway
  • Add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design
  • Use an SLA-aware lowest-cost strategy with correct member cost and health checks
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability

Correct answer: B

Explanation

  1. Performance SLA probes measure member health and quality for SD-WAN decisions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid declaring an internet link healthy when only the directly connected gateway is reachable.
  2. A representative health-check target gives a better indication of end-to-end path usability. This directly satisfies the stated requirement.
  3. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid declaring an internet link healthy when only the directly connected gateway is reachable.
  4. An SLA-aware cost strategy can prefer an inexpensive healthy path and move traffic when that path is no longer acceptable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid declaring an internet link healthy when only the directly connected gateway is reachable.
  5. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid declaring an internet link healthy when only the directly connected gateway is reachable.

Learning point: For this FortiOS 7.6 scenario, probe a target that represents the real service path rather than only the first-hop gateway. A representative health-check target gives a better indication of end-to-end path usability.

Question 25

Fabrikam Manufacturing is standardizing its FortiGate 7.6 operations. Which approach should it use to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone? The team wants the smallest change that directly addresses the requirement.

  • Reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules
  • Add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design
  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability
  • Probe a target that represents the real service path rather than only the first-hop gateway

Correct answer: C

Explanation

  1. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone.
  2. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone.
  3. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This directly satisfies the stated requirement.
  4. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone.
  5. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone.

Learning point: For this FortiOS 7.6 scenario, add or correct the route that makes the destination reachable through the SD-WAN zone or member path. SD-WAN rules influence member selection but do not eliminate the need for valid routing.

Question 26

A production ticket for Wingtip Energy states that administrators must understand what happens when no explicit SD-WAN service rule matches. Which choice is correct? The choice should follow normal FortiOS administration practice.

  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Probe a target that represents the real service path rather than only the first-hop gateway
  • Account for the implicit SD-WAN rule and its configured or default member-selection behavior
  • Configure a Performance SLA health check toward a representative reachable target
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability

Correct answer: C

Explanation

  1. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand what happens when no explicit SD-WAN service rule matches.
  2. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand what happens when no explicit SD-WAN service rule matches.
  3. Unmatched SD-WAN traffic is handled by the implicit rule after explicit rules are evaluated. This directly satisfies the stated requirement.
  4. Performance SLA probes measure member health and quality for SD-WAN decisions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand what happens when no explicit SD-WAN service rule matches.
  5. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to understand what happens when no explicit SD-WAN service rule matches.

Learning point: For this FortiOS 7.6 scenario, account for the implicit SD-WAN rule and its configured or default member-selection behavior. Unmatched SD-WAN traffic is handled by the implicit rule after explicit rules are evaluated.

Question 27

The security team at Lucerne Publishing wants to remove a link from quality-sensitive selection when it exceeds the configured SLA thresholds. Which FortiGate configuration or action most directly meets that goal? The solution must preserve the existing production design where possible.

  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Configure a Performance SLA health check toward a representative reachable target
  • Add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design
  • Use an SLA-aware lowest-cost strategy with correct member cost and health checks
  • Reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules

Correct answer: A

Explanation

  1. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This directly satisfies the stated requirement.
  2. Performance SLA probes measure member health and quality for SD-WAN decisions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to remove a link from quality-sensitive selection when it exceeds the configured SLA thresholds.
  3. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to remove a link from quality-sensitive selection when it exceeds the configured SLA thresholds.
  4. An SLA-aware cost strategy can prefer an inexpensive healthy path and move traffic when that path is no longer acceptable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to remove a link from quality-sensitive selection when it exceeds the configured SLA thresholds.
  5. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to remove a link from quality-sensitive selection when it exceeds the configured SLA thresholds.

Learning point: For this FortiOS 7.6 scenario, use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds.

Question 28

An incident at School of Fine Art requires the security engineer to troubleshoot why a member is not selected despite being physically up. What should be done first? The change is being made during a controlled production window.

  • Configure a Performance SLA health check toward a representative reachable target
  • Use an SLA-aware lowest-cost strategy with correct member cost and health checks
  • Reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules
  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability

Correct answer: E

Explanation

  1. Performance SLA probes measure member health and quality for SD-WAN decisions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot why a member is not selected despite being physically up.
  2. An SLA-aware cost strategy can prefer an inexpensive healthy path and move traffic when that path is no longer acceptable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot why a member is not selected despite being physically up.
  3. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot why a member is not selected despite being physically up.
  4. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot why a member is not selected despite being physically up.
  5. Physical link state alone does not determine SD-WAN selection. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability. Physical link state alone does not determine SD-WAN selection.

Question 29

For a FortiGate 7.6 deployment at Apex Retail, which option correctly addresses the need to send ordinary traffic over the lowest-cost healthy link and fail over when it stops meeting the SLA? The team will validate the result immediately after the change.

  • Reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules
  • Use SD-WAN rules with application or traffic matching and a strategy that considers measured link quality
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability
  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Use an SLA-aware lowest-cost strategy with correct member cost and health checks

Correct answer: E

Explanation

  1. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send ordinary traffic over the lowest-cost healthy link and fail over when it stops meeting the SLA.
  2. SD-WAN can select links per traffic class and measured health instead of using a single static default path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send ordinary traffic over the lowest-cost healthy link and fail over when it stops meeting the SLA.
  3. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send ordinary traffic over the lowest-cost healthy link and fail over when it stops meeting the SLA.
  4. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send ordinary traffic over the lowest-cost healthy link and fail over when it stops meeting the SLA.
  5. An SLA-aware cost strategy can prefer an inexpensive healthy path and move traffic when that path is no longer acceptable. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, use an SLA-aware lowest-cost strategy with correct member cost and health checks. An SLA-aware cost strategy can prefer an inexpensive healthy path and move traffic when that path is no longer acceptable.

Question 30

Proseware Media has validated routing and basic reachability. The remaining requirement is to direct business traffic to one zone without hard-coding a physical interface into every firewall rule. Which action should the team take? No unrelated security controls should be changed.

  • Probe a target that represents the real service path rather than only the first-hop gateway
  • Add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design
  • Account for the implicit SD-WAN rule and its configured or default member-selection behavior
  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules

Correct answer: E

Explanation

  1. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to direct business traffic to one zone without hard-coding a physical interface into every firewall rule.
  2. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to direct business traffic to one zone without hard-coding a physical interface into every firewall rule.
  3. Unmatched SD-WAN traffic is handled by the implicit rule after explicit rules are evaluated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to direct business traffic to one zone without hard-coding a physical interface into every firewall rule.
  4. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to direct business traffic to one zone without hard-coding a physical interface into every firewall rule.
  5. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection.

Question 31

At City Power & Light, a infrastructure engineer is handling a FortiGate 7.6 change. The requirement is to treat several WAN transports as a logical policy-controlled egress. What should the administrator do? The administrator wants a configuration that is easy to audit later.

  • Probe a target that represents the real service path rather than only the first-hop gateway
  • Use SD-WAN rules with application or traffic matching and a strategy that considers measured link quality
  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design
  • Account for the implicit SD-WAN rule and its configured or default member-selection behavior

Correct answer: D

Explanation

  1. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to treat several WAN transports as a logical policy-controlled egress.
  2. SD-WAN can select links per traffic class and measured health instead of using a single static default path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to treat several WAN transports as a logical policy-controlled egress.
  3. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to treat several WAN transports as a logical policy-controlled egress.
  4. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules. This directly satisfies the stated requirement.
  5. Unmatched SD-WAN traffic is handled by the implicit rule after explicit rules are evaluated. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to treat several WAN transports as a logical policy-controlled egress.

Learning point: For this FortiOS 7.6 scenario, add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules.

Question 32

During a maintenance window at Margie Travel, the team must prefer a high-quality link for latency-sensitive applications while retaining another link for resilience. Which action is the most appropriate? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.

  • Use SD-WAN rules with application or traffic matching and a strategy that considers measured link quality
  • Add the eligible interfaces or tunnels as SD-WAN members and use an SD-WAN zone in policy and routing design
  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Probe a target that represents the real service path rather than only the first-hop gateway
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability

Correct answer: A

Explanation

  1. SD-WAN can select links per traffic class and measured health instead of using a single static default path. This directly satisfies the stated requirement.
  2. SD-WAN combines member links into logical zones that can be selected by SD-WAN rules. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer a high-quality link for latency-sensitive applications while retaining another link for resilience.
  3. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer a high-quality link for latency-sensitive applications while retaining another link for resilience.
  4. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer a high-quality link for latency-sensitive applications while retaining another link for resilience.
  5. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer a high-quality link for latency-sensitive applications while retaining another link for resilience.

Learning point: For this FortiOS 7.6 scenario, use SD-WAN rules with application or traffic matching and a strategy that considers measured link quality. SD-WAN can select links per traffic class and measured health instead of using a single static default path.

Question 33

A change review at Bellows College identifies one requirement: measure whether a WAN member meets latency, jitter, and packet-loss requirements. Which FortiGate action best satisfies it? The team wants the smallest change that directly addresses the requirement.

  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability
  • Use SD-WAN rules with application or traffic matching and a strategy that considers measured link quality
  • Use an SLA-aware lowest-cost strategy with correct member cost and health checks
  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Configure a Performance SLA health check toward a representative reachable target

Correct answer: E

Explanation

  1. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure whether a WAN member meets latency, jitter, and packet-loss requirements.
  2. SD-WAN can select links per traffic class and measured health instead of using a single static default path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure whether a WAN member meets latency, jitter, and packet-loss requirements.
  3. An SLA-aware cost strategy can prefer an inexpensive healthy path and move traffic when that path is no longer acceptable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure whether a WAN member meets latency, jitter, and packet-loss requirements.
  4. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure whether a WAN member meets latency, jitter, and packet-loss requirements.
  5. Performance SLA probes measure member health and quality for SD-WAN decisions. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, configure a Performance SLA health check toward a representative reachable target. Performance SLA probes measure member health and quality for SD-WAN decisions.

Question 34

While troubleshooting at Adventure Works, the security engineer needs to avoid declaring an internet link healthy when only the directly connected gateway is reachable. What is the best next step? The choice should follow normal FortiOS administration practice.

  • Configure a Performance SLA health check toward a representative reachable target
  • Reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules
  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability
  • Probe a target that represents the real service path rather than only the first-hop gateway

Correct answer: E

Explanation

  1. Performance SLA probes measure member health and quality for SD-WAN decisions. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid declaring an internet link healthy when only the directly connected gateway is reachable.
  2. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid declaring an internet link healthy when only the directly connected gateway is reachable.
  3. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid declaring an internet link healthy when only the directly connected gateway is reachable.
  4. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid declaring an internet link healthy when only the directly connected gateway is reachable.
  5. A representative health-check target gives a better indication of end-to-end path usability. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, probe a target that represents the real service path rather than only the first-hop gateway. A representative health-check target gives a better indication of end-to-end path usability.

Question 35

Fourth Coffee is standardizing its FortiGate 7.6 operations. Which approach should it use to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone? The solution must preserve the existing production design where possible.

  • Check SD-WAN rule match, Performance SLA state, member cost or priority, and route availability
  • Use Performance SLA state in an SD-WAN rule so out-of-SLA members are avoided according to the selected strategy
  • Add or correct the route that makes the destination reachable through the SD-WAN zone or member path
  • Reference the SD-WAN zone in the firewall policy and control member choice with SD-WAN rules
  • Probe a target that represents the real service path rather than only the first-hop gateway

Correct answer: C

Explanation

  1. Physical link state alone does not determine SD-WAN selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone.
  2. SLA status lets FortiGate distinguish healthy links from links that fail required performance thresholds. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone.
  3. SD-WAN rules influence member selection but do not eliminate the need for valid routing. This directly satisfies the stated requirement.
  4. Using a zone decouples policy from individual WAN members and lets SD-WAN make the egress selection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone.
  5. A representative health-check target gives a better indication of end-to-end path usability. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an SD-WAN rule that matches traffic but no route exists through the SD-WAN zone.

Learning point: For this FortiOS 7.6 scenario, add or correct the route that makes the destination reachable through the SD-WAN zone or member path. SD-WAN rules influence member selection but do not eliminate the need for valid routing.

Popular posts

img