Fortinet FCSS_SDW_AR-7.6 - FCSS - SD-WAN 7.6 Architect Exam
Page: 1 / 8
Total 36 questions
Question #1 (Topic: Exam A)
Refer to the exhibit.
FortiManager SD-WAN monitor

To check the status of an SD-WAN topology using the FortiManager SD-WAN monitor menus, you place your mouse next to branch1_fgt and receive the output shown in the exhibit.
Which conclusion can you draw from the output shown in the exhibit?
FortiManager SD-WAN monitor

To check the status of an SD-WAN topology using the FortiManager SD-WAN monitor menus, you place your mouse next to branch1_fgt and receive the output shown in the exhibit.
Which conclusion can you draw from the output shown in the exhibit?
A. Three tunnels of branch2_fgt are out of SLA.
B. The template Corp-SOT defines a single-hub topology.
C. branch3_fgt is configured with three SD-WAN overlay tunnels and one is dead.
D. The three spokes have tunnels that are out of SLA.
Answer: D
Question #2 (Topic: Exam A)
Refer to the exhibit, which shows the SD-WAN rule status and configuration.
SD-WAN rules status and configuration

Based on the exhibit, which change in the measured packet loss will make HUB1-VPN3 the new preferred member?
SD-WAN rules status and configuration

Based on the exhibit, which change in the measured packet loss will make HUB1-VPN3 the new preferred member?
A. When all three members have the same packet loss
B. When HUB1-VPN3 has 4% packet loss
C. When HUB1-VPN1 has 12% packet loss
D. When HUB1-VPN1 has 4% packet loss
Answer: C
Question #3 (Topic: Exam A)
Refer to the exhibits.
Global System configuration

Interface port2 configuration

Routing Table on FortiGate

The administrator increases the member priority on port2 to 20.
Upon configuration changes and the receipt of new packets, which two actions does FortiGate perform on existing sessions established over port2? (Choose two.)
Global System configuration

Interface port2 configuration

Routing Table on FortiGate

The administrator increases the member priority on port2 to 20.
Upon configuration changes and the receipt of new packets, which two actions does FortiGate perform on existing sessions established over port2? (Choose two.)
A. FortiGate continues routing all existing sessions over port2.
B. FortiGate routes only new sessions over port2.
C. FortiGate flags the sessions as dirty.
D. FortiGate updates the gateway information of the sessions with SNAT so that they use port1 instead of port2.
E. FortiGate flags the SNAT session as dirty only if the administrator has assigned an IP pool to the firewall policies with NAT.
Answer: CD
Question #4 (Topic: Exam A)
You are configuring ADVPN 2.0 on an SD-WAN topology already configured for ADVPN.
What should you do to implement ADVPN 2.0 in this scenario?
What should you do to implement ADVPN 2.0 in this scenario?
A. Update the IPsec tunnel configuration on the branches.
B. Delete the existing ADVPN configuration and configure ADVPN 2.0.
C. Update the IPsec tunnel configurations on the hub.
D. Update the SD-WAN configuration on the branches.
Answer: C
Question #5 (Topic: Exam A)
As an IT manager, you want to delegate the installation and management of your SD-WAN deployment to a managed security service provider (MSSP).
Each site must maintain direct internet access and be secure. You expect significant traffic flow between the sites and want to delegate as much of the network administration and management as possible to the MSSP.
Which two MSSP deployment blueprints address your requirements? (Choose two.)
Each site must maintain direct internet access and be secure. You expect significant traffic flow between the sites and want to delegate as much of the network administration and management as possible to the MSSP.
Which two MSSP deployment blueprints address your requirements? (Choose two.)
A. Install the hub and spokes on the customer premises, and enable the MSSP to manage the SD-WAN deployment using FortiManager with a dedicated ADOM.
B. Use a shared hub on the MSSP premises and a dedicated hub on the customer premises, and install the spokes on the customer premises.
C. Install a dedicated hub on the MSSP premises for the customer, and install the spokes on the customer premises.
D. Use a shared hub on the MSSP premises with a dedicated VDOM for the customer, and install the spokes on the customer premises.
Answer: CD