Download Fortinet NSE 7 -SD-WAN 7-2.NSE7_SDW-7.2.ExamTopics.2025-08-07.70q.tqb

Vendor: Fortinet
Exam Code: NSE7_SDW-7.2
Exam Name: Fortinet NSE 7 -SD-WAN 7-2
Date: Aug 07, 2025
File Size: 8 MB

How to open TQB files?

Files with TQB (Taurus Question Bank) extension can be opened by Taurus Exam Studio.

Demo Questions

Question 1
Which are three key routing principles in SD-WAN? (Choose three.)
  1. By default. SD-WAN members are skipped if they do not have a valid route to the destination.
  2. By default. SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.
  3. FortiGate performs route lookups for new sessions only.
  4. SD-WAN rules have precedence over ISDB routes.
  5. Regular policy routes have precedence over SD-WAN rules.
Correct answer: ABE
Explanation:
ABE: 16 - MostedBDE: 1
ABE: 16 - MostedBDE: 1
Question 2
Refer to the exhibit.
  1. FortiGate does not change the routing information on existing sessions that use a valid gateway, after a route change.
  2. FortiGate always blocks all traffic, after a route change.
  3. FortiGate performs routing lookups for new sessions only, after a route change.
  4. FortiGate flushes all routing information from the session table, after a route change.
Correct answer: A
Explanation:
A: 12 - MostedC: 1
A: 12 - MostedC: 1
Question 3
Refer to the exhibit.
The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths. However, when looking at the spoke routing table, the administrator does not see the prefixes from other spokes and the additional paths.
Based on the exhibit, which three settings must the administrator configure inside each BGP neighbor group so spokes can learn other spokes prefixes and their additional paths? (Choose three.)
  1. Enable soft-reconfiguration
  2. Enable route-reflector-client
  3. Set additional-path to send
  4. Set adv-additional-path to the number of additional paths to advertise
  5. Set advertisement-interval to the number of additional paths to advertise
Correct answer: BCD
Explanation:
BCD: 7 - Mosted
BCD: 7 - Mosted
Question 4
What are two advantages of using an IPsec recommended template to configure an IPsec tunnel in an hub-and-spoke topology? (Choose two.)
  1. It ensures consistent settings between phase1 and phase2.
  2. It guides the administrator to use Fortinet recommended settings.
  3. The VPN monitor tool provides additional statistics for tunnels defined with an IPsec recommended template.
  4. It automatically install IPsec tunnels to every spoke when they are added to the FortiManager ADOM.
Correct answer: AB
Explanation:
AB: 8 - Mosted
AB: 8 - Mosted
Question 5
In a hub-and-spoke topology, what are two advantages of enabling ADVPN on the IPsec overlays? (Choose two.)
  1. It provides the benefits of a full-mesh topology in a hub-and-spoke network.
  2. It enables spokes to establish shortcuts to third-party gateways.
  3. It provides direct connectivity between spokes by creating shortcuts.
  4. It enables spokes to bypass the hub during shortcut negotiation.
Correct answer: AC
Explanation:
AC: 3 - Mosted
AC: 3 - Mosted
Question 6
Refer to the exhibit.
The exhibit shows output of the command diagnose sys sdwan service collected on a FortiGate device.
The administrator wants to know through which interface FortiGate will steer the traffic from local users on subnet 10.0.1.0/255.255.255.192 and with a destination of the business application Salesforce located on HQ servers 10.0.0.1.
Based on the exhibits, which two statements are correct? (Choose two.)
  1. There is no service defined for the Salesforce application, so FortiGate will use the service rule 3 and steer the traffic through interface T_HQ1.
  2. FortiGate steers traffic to HQ servers according to service rule 1 and it uses port1 or port2 because both interfaces are selected.
  3. When FortiGate cannot recognize the application of the flow it steers the traffic destined to server 10.0.0.1 according to service rule 3.
  4. FortiGate steers traffic for business application according to service rule 2 and steers traffic through port2.
Correct answer: CD
Explanation:
AC: 13AD: 1C: 1CD: 15 - Mosted
AC: 13AD: 1C: 1CD: 15 - Mosted
Question 7
Refer to the exhibit.
Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2.
Which two configuration settings are required for Toronto and London spokes to establish an ADVPN shortcut? (Choose two.)
  1. On the hubs, net-device must be enabled on all IPsec VPNs.
  2. auto-discovery-forwarder must be enabled on all IPsec VPNs.
  3. On the spokes, auto-discovery-receiver must be enabled on the IPsec VPN to the hub.
  4. On the hubs, auto-discovery-sender must be enabled on the IPsec VPNs to spokes.
Correct answer: CD
Explanation:
CD: 11 - Mosted
CD: 11 - Mosted
Question 8
Which CLI command do you use to perform real-time troubleshooting for ADVPN negotiation?
  1. get router info routing-table all
  2. get ipsec tunnel list
  3. diagnose vpn tunnel list
  4. diagnose debug application ike
Correct answer: D
Explanation:
D: 6 - Mosted
D: 6 - Mosted
Question 9
What are two common use cases for remote internet access (RIA)? (Choose two.)
  1. Provide internet access through the hub.
  2. Centralize security inspection on the hub.
  3. Provide thorough inspection on spokes.
  4. Provide direct internet access on spokes.
Correct answer: AB
Explanation:
AB: 10 - Mosted
AB: 10 - Mosted
Question 10
Refer to the exhibits.
Exhibit A.
Exhibit B.
An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in exhibit A.
After generating GoToMeeting test traffic, the administrator examined the respective traffic log on FortiAnalyzer, which is shown in exhibit B. The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.
Which two reasons explain why some log messages show that the traffic matched the implicit SD-WAN rule? (Choose two.)
  1. Port1 and port2 do not have a valid route to the destination.
  2. The session 3-tuple did not match any of the existing entries in the ISDB application cache.
  3. Full SSL inspection is not enabled on the matching firewall policy.
  4. FortiGate did not refresh the routing information on the session after the application was detected.
Correct answer: BD
Explanation:
BD: 7 - Mosted
BD: 7 - Mosted
HOW TO OPEN VCE FILES

Use VCE Exam Simulator to open VCE files
Avanaset

HOW TO OPEN VCEX FILES

Use ProfExam Simulator to open VCEX files
ProfExam Screen

ProfExam
ProfExam at a 20% markdown

You have the opportunity to purchase ProfExam at a 20% reduced price

Get Now!