Fortinet nse7-sdw-7-0 practice test

Exam Title: Fortinet NSE 7 - SD-WAN 7.0

Last update: Dec 25 ,2025
Question 1

Which are two benefits of using CLI templates in FortiManager? (Choose two.)

  • A. You can reference meta fields.
  • B. You can configure interfaces as SD-WAN members without having to remove references first.
  • C. You can configure FortiManager to sync local configuration changes made on the managed device, to the CLI template.
  • D. You can configure advanced CLI settings.
Answer:

ad

vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Question 2

Which two interfaces are considered overlay links? (Choose two.)

  • A. LAG
  • B. IPsec
  • C. Physical
  • D. GRE
Answer:

bd

vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Question 3

Which CLI command do you use to perform real-time troubleshooting for ADVPN negotiation?

  • A. get router info routing-table all
  • B. diagnose debug application ike
  • C. diagnose vpn tunnel list
  • D. get ipsec tunnel list
Answer:

b

vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Question 4

What does enabling the exchange-interface-ip setting enable FortiGate devices to exchange?

  • A. The gateway address of their IPsec interfaces
  • B. The tunnel ID of their IPsec interfaces
  • C. The IP address of their IPsec interfaces
  • D. The name of their IPsec interfaces
Answer:

c

vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Question 5

Refer to the exhibit.



The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths. However, when looking at the spoke routing table, the administrator does not see the prefixes from other spokes and the additional paths.

Based on the exhibit, which three settings must the administrator configure inside each BGP neighbor group so spokes can learn other spokes prefixes and their additional paths? (Choose three.)

  • A. Set additional-path to send
  • B. Enable route-reflector-client
  • C. Set advertisement-interval to the number of additional paths to advertise
  • D. Set adv-additional-path to the number of additional paths to advertise
  • E. Enable soft-reconfiguration
Answer:

abc

vote your answer:
A
B
C
D
E
A 0 B 0 C 0 D 0 E 0
Comments
Question 6

Refer to the exhibit.

Which conclusion about the packet debug flow output is correct?

  • A. The total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
  • B. The packet size exceeded the outgoing interface MTU.
  • C. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
  • D. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the firewall policy, and the packet was dropped.
Answer:

c

vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Question 7

Refer to the exhibit.

The exhibit shows the SD-WAN rule status and configuration.
Based on the exhibit, which change in the measured latency will make T_MPLS_0 the new preferred member?

  • A. When T_INET_0_0 and T_MPLS_0 have the same latency.
  • B. When T_MPLS_0 has a latency of 100 ms.
  • C. When T_INET_0_0 has a latency of 250 ms.
  • D. When T_N1PLS_0 has a latency of 80 ms.
Answer:

d

vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Question 8

Which statement is correct about SD-WAN and ADVPN?

  • A. Routes for ADVPN shortcuts must be manually configured.
  • B. SD-WAN can steer traffic to ADVPN shortcuts, established over IPsec overlays, configured as SD-WAN members.
  • C. SD-WAN does not monitor the health and performance of ADVPN shortcuts.
  • D. You must use IKEv2 on IPsec tunnels.
Answer:

b

vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Question 9

Refer to the exhibits.


Which two statements about the IPsec VPN configuration and the status of the IPsec VPN tunnel are true? (Choose two.)

  • A. FortiGate does not install IPsec static routes for remote protected networks in the routing table.
  • B. The phase 1 configuration supports the network-overlay setting.
  • C. FortiGate facilitated the negotiation of the T_INET_1_0_0 ADVPN shortcut over T_INET_1_0.
  • D. Dead peer detection is disabled.
Answer:

ac

vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Question 10

Which best describes the SD-WAN traffic shaping mode that bases itself on a percentage of available bandwidth?

  • A. Interface-based shaping mode
  • B. Reverse-policy shaping mode
  • C. Shared-policy shaping mode
  • D. Per-IP shaping mode
Answer:

a

vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Page 1 out of 3
Viewing questions 1-10 out of 39
Go To
page 2