Pre-Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

NSE6_SDW_AD-7.6 Fortinet NSE 6 - SD-WAN 7.6 Enterprise Administrator Questions and Answers

Questions 4

Which three factors about SLA targets and SD-WAN rules should you consider when configuring SD-WAN rules? (Choose three.)

Options:

A.

Member metrics are measured only if a rule uses the SLA target.

B.

SLA targets are used only by SD-WAN rules that are configured with a Lowest Cost (SLA) strategy.

C.

SD-WAN rules can use SLA targets to check whether the preferred members meet the SLA requirements.

D.

When configuring an SD-WAN rule, you can select multiple SLA targets if they are from the same performance SLA.

E.

When configuring an SD-WAN rule, you can select multiple SLA targets from different performance SLAs.

Buy Now
Questions 5

(Which two features must you configure before FortiGate can steer traffic according to SD-WAN rules? Choose two answers.)

Options:

A.

Security profiles

B.

Underlay links

C.

Overlay links

D.

Traffic shaping

E.

Firewall policies

Buy Now
Questions 6

Refer to the exhibits.

NSE6_SDW_AD-7.6 Question 6

The exhibits show the configuration for SD-WAN performance. SD-WAN rule, the application IDs of Facebook and YouTube along with the firewall policy configuration and the underlay zone status.

Which two statements are true about the health and performance of SD-WAN members 3 and 4? (Choose two.)

Options:

A.

Only related TCP traffic is used for performance measurement.

B.

The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.

C.

Encrypted traffic is not used for the performance measurement.

D.

FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.

Buy Now
Questions 7

(When you deploy SD-WAN, you can choose from several common designs. Each design best applies to specific contexts.

Which two statements correctly associate a common SD-WAN design with its main indication or constraint? Choose two answers.)

Options:

A.

Use a cloud on-ramp topology to improve the performance of cloud applications.

B.

Use a standalone design for sites with only one WAN link to the cloud.

C.

Use remote breakout to centralize traffic inspection and limit local management requirements.

D.

Use a direct internet access (DIA) design to increase the traffic security and allow local devices with limited capabilities.

Buy Now
Questions 8

NSE6_SDW_AD-7.6 Question 8

Refer to the exhibit that shows event logs on FortiGate.

Based on the output shown in the exhibit, what can you say about the tunnels on this device?

Options:

A.

The master tunnel HU82-VPN3 cannot accept ADVPN shortcuts.

B.

The device steers voice traffic through the VPN tunnel HUB1-VPN3.

C.

The VPN tunnel HUB1-VPN1_0 is a shortcut tunnel.

D.

There is one shortcut tunnel built from master tunnel VPN4.

Buy Now
Questions 9

Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 9

What conclusions can you draw about the traffic received by FortiGate originating from the source LAN device 10.0.1.133 and destined for the company’s SMTP mail server at 10.66.0.125?

Options:

A.

FortiGate steers the traffic from the LAN device 10.0.1.133 to the company SMTP mail server 10.66 0.125 through port3.

B.

ForliGate steers the traffic from the LAN device 10.0.1.133 to the company SMTP mail server 10.66.0.125 through port2.

C.

FortiGate steers the traffic from the LAN device 10.0.1.133 to the company SMTP mail server 10.66.0.125 through the SD-WAN member ID 4.

D.

FortiGate steers the traffic from the LAN device 10.0.1.133 to the SMTP mail server 10.66.0.125 through the SD-WAN member ID 1 or 2.

Buy Now
Questions 10

Refer to the exhibits.

NSE6_SDW_AD-7.6 Question 10

You connect to a device behind a branch FortiGate device and initiate a ping test. The device is part of the LAN subnet and its IP address is 10.0.1.101.

Based on the exhibits, which interface uses branch 1_fgt to steer the test traffic?

Options:

A.

port4

B.

HUB1-VPN1

C.

port1

D.

port2

Buy Now
Questions 11

Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 11

Which statement best describe the role of the ADVPN device in handling traffic?

Options:

A.

This is a hub that has received a query from a spoke and has forwarded it to another spoke.

B.

This is a hub in a dual-region topology. The remote hub tunnel ID is 10.0.2.101.

C.

This is a spoke that has received a shortcut query from another spoke and has forwarded the response to its hub.

D.

This is a spoke. The kernel received a shortcut request and forwards the query to another spoke.

Buy Now
Questions 12

SD-WAN interacts with many other FortiGate features. Some of them are required to allow SD-WAN to steer the traffic.

Which three configuration elements that you must configure before FortiGate can steer traffic according to SD-WAN rules? (Choose three.)

Options:

A.

Firewall policies

B.

Interfaces

C.

Security profiles

D.

Traffic shaping

E.

Routing

Buy Now
Questions 13

(In which order does FortiGate consider the following elements during the route lookup process? Choose one answer.)

Options:

A.

SD-WAN rules, ISDB routes, policy routes, BGP routes

B.

Policy routes, SD-WAN rules, Internet Service Database (ISDB) routes, BGP routes

C.

SD-WAN rules, policy routes, static routes, ISDB routes

D.

Policy routes, ISDB routes, SD-WAN rules, static routes

Buy Now
Questions 14

What are three key routing principles of SD-WAN? (Choose three.)

Options:

A.

Directly connected routes have precedence over SD-WAN rules.

B.

Policy routes have precedence over SD-WAN rules.

C.

SD-WAN rules are skipped if the best route to the destination is a static route

D.

SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.

E.

SD-WAN members are skipped if they do not have a valid route to the destination.

Buy Now
Questions 15

NSE6_SDW_AD-7.6 Question 15

Refer to the exhibit.

You want to configure SD-WAN on a network as shown in the exhibit.

The network contains many FortiGate devices. Some are used as NGFW, and some are installed with extensions such as FortiSwitch. FortiAP. or Forti Ex tender.

What should you consider when planning your deployment?

Options:

A.

You can build an SD-WAN topology that includes all devices. The hubs can be FortiGate devices with Forti Extender.

B.

You can build an SD-WAN topology that includes all devices. The hubs must be devices without extensions.

C.

You must use FortiManager to manage your SD-WAN topology.

D.

You must build multiple SD-WAN topologies. Each topology must contain only one type of extension.

Buy Now
Questions 16

Exhibit.

NSE6_SDW_AD-7.6 Question 16

Refer to the exhibit, which shows the SD-WAN rule status and configuration.

Based on the exhibit, which change in the measured packet loss will make HUB1-VPN3 the new preferred member?

Options:

A.

When HUB1-VPN1 has 4% packet loss

B.

When HUB1-VPN1 has 12% packet loss

C.

When HUB1-VPN3 has 4% packet loss

D.

When all three members have the same packet loss

Buy Now
Questions 17

Within the context of SD-WAN, what does SIA correspond to?

Options:

A.

Remote Breakout

B.

Local Breakout

C.

Software Internet Access

D.

Secure Internet Authorization

Buy Now
Questions 18

Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 18

Which two conclusions can you draw from the output shown? (Choose two.)

Options:

A.

One SD-WAN rule is defined with application categories as the destination.

B.

UDP traffic destined to the subnet 10.22.0.0/24 matches a manual SD-WAN rule.

C.

One SD-WAN rule allows traffic load balancing.

D.

UDP traffic destined to the subnet 10.22.0.0/24 matches a policy route.

Buy Now
Questions 19

Refer to the exhibits.

NSE6_SDW_AD-7.6 Question 19

NSE6_SDW_AD-7.6 Question 19

NSE6_SDW_AD-7.6 Question 19

The exhibits show an SD-WAN event log, the member status, and the SD-WAN rule configuration.

Which two conclusions can you draw from the information shown? (Choose two.)

Options:

A.

The administrator configured the service ID 1 with the highest priority member for port2.

B.

Port2 has a lower latency than port1.

C.

FortiGate updated the outgoing interface list on the rule so it prefers port2.

D.

The administrator configured the SD-WAN rule ID 1 with the default strategy mode.

Buy Now
Questions 20

Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 20

The administrator used the SD-WAN overlay template to prepare an IPsec tunnels configuration for a hub-and-spoke SD-WAN topology. The exhibit shows the FortiManager installation preview for one FortiGate device.

Based on the exhibit, which statement best describes the configuration applied to the FortiGate device?

Options:

A.

It is a spoke device that establishes dynamic IPsec tunnels to the hub. The local subnet range is 10.10.128.0/23.

B.

It is a hub device. It can send ADVPN shortcut offers.

C.

It is a hub device. It will automatically discover the spoke devices and add them to the SD-WAN topology.

D.

It is a spoke device that establishes dynamic IPsec tunnels to the hub It can send ADVPN shortcut requests.

Buy Now
Questions 21

Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 21

An administrator configures SD-WAN rules for a DIA setup using the FortiGate GUI. The page to configure the source and destination part of the rule looks as shown in the exhibit. The GUI page shows no option to configure an application as the destination of the SD-WAN rule Why?

Options:

A.

You cannot use applications as the destination when FortiGate is used for a DIA setup.

B.

FortiGate allows the configuration of applications as the destination of SD-WAN rules only on the CLI.

C.

You must enable the feature on the CLI.

D.

You must enable the feature first using the GUI menu System > Feature Visibility.

Buy Now
Questions 22

(Refer to the exhibits. You collected the output shown in the exhibits and want to know which interface TCP traffic will flow through from the user device 10.0.1.101 to the corporate file server 10.0.0.125 . All SD-WAN links are stable.

NSE6_SDW_AD-7.6 Question 22

Which interface will FortiGate use to steer the traffic? Choose one answer.)

Options:

A.

Only HUB1-VPN1

B.

Either HUB1-VPN1 or HUB1-VPN2

C.

Only HUB1-VPN2

D.

Either HUB1-VPN1 , HUB1-VPN2 , or HUB1-VPN3

Buy Now
Questions 23

Refer to the exhibits.

NSE6_SDW_AD-7.6 Question 23

To prepare to onboard FortiGate devices to your company ' s stores, you configure the device blueprint and CLI scripts shown in the exhibit. Then, a technician prepares a FortiGate 90G with a basic configuration and connects it to the network. The basic configuration contains the port1 configuration and the minimal configuration required to allow the device to connect to FortiManager.

After the device initially connects to FortiManager, FortiManager updates the device configuration.

Based on what is shown in the exhibits, which statement about the actions taken by FortiManager is true?

Options:

A.

FortiManager updates the configuration of port1, port2, and port5. The three ports might get new IP addresses

B.

FortiManager updates access rights only for port1. FortiManager cannot update the IP address because it was already set manually

C.

FortiManager updates the device configuration according to the selected templates and it applies the corp_st template first

D.

FortiManager does not update the port1 configuration because FortiManager does not change the configuration of interfaces with FortiGate-FortiManager communication protocol (FGFM) access

Buy Now
Questions 24

To secure your enterprise network traffic, which step does FortiGate perform first, when handling the first packets of a session? (Choose one answer)

Options:

A.

Installation of the session key in the network processor (NP)

B.

Decryption

C.

A reverse path forwarding (RPF) check

D.

IP integrity header checking

Buy Now
Questions 25

The FortiGate devices are managed by ForliManager, and are configured for direct internet access (DIA). You confirm that DIA is working as expected for each branch, and check the SD-WAN zone configuration and firewall policies shown in the exhibits.

NSE6_SDW_AD-7.6 Question 25

NSE6_SDW_AD-7.6 Question 25

NSE6_SDW_AD-7.6 Question 25

Then, you use the SD-WAN overlay template to configure the IPsec overlay tunnels. You create the associated SD-WAN rules to connect existing branches to the company hub device and apply the changes on the branches.

After those changes, users complain that they lost internet access. DIA is no longer working.

Based on the exhibit, which statement best describes the possible root cause of this issue?

Options:

A.

The SD-WAN overlay template defines a zone for each underlay interface and moves the interfaces into those zones.

B.

The SD-WAN overlay template didn’t configure a firewall policy to allow traffic through the overlay.

C.

The SD-WAN overlay template redefines the interface gateway addresses if they are defined with metadata variables.

D.

The SD-WAN overlay template updates the SD-WAN template and the rules.

Buy Now
Questions 26

Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 26

The administrator configured the SD-WAN rule ID 4 with two members (port1 and port2) and strategy lowest cost (SLA).

What are the two characteristics of the session shown in the exhibit? (Choose two.)

Options:

A.

FortiGate steered this flow according to an SD-WAN rule 4.

B.

FortiGate will never re-evaluate this session.

C.

FortiGate steered this flow according to the application detected and the outgoing interface is port3.

D.

FortiGate will re-evaluate this session if the outgoing interface goes down.

Buy Now
Questions 27

You used the HUB IPsec_Recommended and the BRANCH IPsec_Recommended templates to define the overlay topology. Then, you used the SD-WAN template to define the SD- WAN members, rules, and performance SLAs.

You applied the changes to the devices and want to use the FortiManager monitors menu to get a graphical view that shows the status of each SD-WAN member.

Which statement best explains how to obtain this graphical view?

Options:

A.

Use the SD-WAN monitor template view to get a map view of the branches, hub, and tunnel status, including the SLA pass or missed status.

B.

Use the SD-WAN monitor table view to get a donut view and a table view that shows the status of each SD-WAN member, including the SLA pass or missed status.

C.

Use the VPN monitor map view to get a map view of the branches, hub, and tunnel status, including the SLA pass or missed status.

D.

Use the SD-WAN monitor asset view to get a donut view and a table view that shows the status of each device and the SLA status of each SD-WAN member.

Buy Now
Questions 28

(Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 28

What can you conclude from the output shown? Choose one answer.)

Options:

A.

It is a spoke device. SD-WAN rule 3 is configured with nine members.

B.

It is a spoke device. The members of SD-WAN rule 3 are grouped into two zones.

C.

It is a hub device. It allowed the establishment of three auto-discovery VPN (ADVPN) shortcuts.

D.

It is a spoke device. SD-WAN rule 4 allows three shortcut tunnels.

Buy Now
Exam Code: NSE6_SDW_AD-7.6
Exam Name: Fortinet NSE 6 - SD-WAN 7.6 Enterprise Administrator
Last Update: Apr 30, 2026
Questions: 96

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99