[Q48-Q70] Top Fortinet NSE6_SDW_AD-7.6 Courses Online - Updated [Apr-2026]

Share

Top Fortinet NSE6_SDW_AD-7.6 Courses Online - Updated [Apr-2026]

NSE6_SDW_AD-7.6 Practice Dumps - Verified By TestInsides Updated 97 Questions

NEW QUESTION # 48
Which two statements correctly describe what happens when traffic matches the implicit SD-WAN rule?
(Choose two.)

  • A. The traffic is distributed, regardless of weight, through all available static routes.
  • B. Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.
  • C. The session information output displays no SD-WAN service id.
  • D. Traffic does not match any of the entries in the policy route table.
  • E. FortiGate flags the session with may_dirty and vwl_def ault.

Answer: C,D

Explanation:
The implicit SD-WAN rule serves as the final catch-all. Per Fortinet:
"Sessions matching the implicit SD-WAN rule do not have an SD-WAN service id, as they are not associated with any specific user-defined SD-WAN rule. Additionally, this occurs only when traffic fails to match any entry in the policy route table. This default handling guarantees connectivity while minimizing the risk of blackholed traffic." Administrators can observe this in diagnostic outputs for troubleshooting.


NEW QUESTION # 49
You are planning a new SD-WAN deployment with the following criteria:
- Two regions
- Most of the traffic is expected to remain within its region
- No requirement for inter-region ADVPN
To remain within the recommended best practices, which routing protocol should you select for the overlays?

  • A. IBGP with BGP on loopback within each region and EBGP between the regions.
  • B. IBGP with BGP per overlays within each region and IBGP with BGP on loopback between the regions.
  • C. OSPF for the routing within each region and EBGP between the regions.
  • D. IBGP within each region and between the regions.

Answer: A

Explanation:
For SD-WAN deployments that span multiple regions-where most traffic is intra-region and there is no requirement for inter-region ADVPN-the best practice is to use IBGP with BGP on loopback interfaces for routing within each region and EBGP between the regions. This approach ensures robust and scalable routing, isolates regional routing domains, and enables policy control at region boundaries. BGP on loopback is preferred for its reliability and flexibility, as it enables peering that is not tied to specific physical interfaces.
EBGP between regions allows each region to maintain independent routing policies and summarization, optimizing performance and manageability. By separating IBGP (intra-region) and EBGP (inter-region), you create a modular architecture that scales easily and simplifies fault isolation and troubleshooting.
References:
[FCSS_SDW_AR-7.4 1-0.docx Q10]
Fortinet SD-WAN Reference Architecture Guide 7.4, "Regional Routing Best Practices" FortiOS 7.4 SD-WAN Overlay Design Guidelines


NEW QUESTION # 50
Refer to the exhibits.

An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in the first exhibit. After generating GoToMeeting test traffic, the administrator examined the corresponding traffic log on FortiAnalyzer, which is shown in the second exhibit.
The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.
Which two reasons explain why some log messages show that the traffic matched the implicit SD-WAN rule?
(Choose two.)

  • A. No configured SD-WAN rule matches the traffic related to the collaboration application GoToMeeting
  • B. Full SSL inspection is not enabled on the matching firewall policy.
  • C. The session 3-tuple did not match any of the existing entries in the ISDB application cache.
  • D. FortiGate could not refresh the routing information on the session after the application was detected.

Answer: A,C


NEW QUESTION # 51
(You want to configure two static routes: one that references an SD-WAN zone and a second one that references an SD-WAN member that belongs to that zone.
Which statement about this scenario is true? Choose one answer.)

  • A. The destination subnets must be different.
  • B. You cannot create static routes for individual SD-WAN members.
  • C. You cannot create static routes that reference an SD-WAN zone.
  • D. The source subnets must be different.

Answer: A

Explanation:
In FortiOS 7.6, static routes can reference either:
* an SD-WAN zone (for example, virtual-wan-link or a user-defined SD-WAN zone), or
* a specific SD-WAN member interface that belongs to that zone.
However, FortiOS enforces a routing constraint to avoid ambiguity during route resolution. Two static routes cannot have the same destination prefix if one points to an SD-WAN zone and the other points to an SD- WAN member within that zone. This would create an overlapping and conflicting forwarding decision.
Therefore, if you configure:
* one static route that references an SD-WAN zone, and
* another static route that references an SD-WAN member belonging to that same zone, the destination subnets of the two static routes must be different.
Why the other options are incorrect:
* Option A is incorrect because FortiOS does allow static routes that reference individual SD-WAN members.
* Option B is incorrect because static routes can reference SD-WAN zones.
* Option D is incorrect because static routing decisions in FortiOS are based on destination prefixes, not source prefixes.
Thus, the correct answer is C.


NEW QUESTION # 52
Refer to the exhibits, which show the configuration of an SD-WAN rule and the corresponding rule status and routing table.


The administrator wants to understand the expected behavior for traffic matching the SD-WAN rule.
Based on the exhibits, what can the administrator expect for traffic matching the SD-WAN rule?

  • A. The traffic will be routed over HUB1-VPN2
  • B. The traffic will be routed over HUB1-VPN1.
  • C. The traffic will be routed over HUB1-VPN3.
  • D. The traffic will be load balanced across all three overlays

Answer: A

Explanation:
The rule is in SLA mode with two SLAs. From the status, HUB1-VPN2 and HUB1-VPN3 meet the SLA (sla (0x2) and sla(0x3)), while HUB1-VPN1 does not (sla(0x0)). Among members that meet SLA, FortiGate uses the configured order (priority-members 4 5 6) to pick the first eligible one-HUB1-VPN2-so traffic is routed over HUB1-VPN2.


NEW QUESTION # 53
Refer to the exhibit.

Which SD-WAN rule and interface uses FortiGate to steer the traffic from the LAN subnet 10.0.1.0/24 to the corporate server 10.2.5.254?

  • A. SD-WAN service rule 3 and interface HUB1-VPN3.
  • B. SD-WAN service rule 4 and interface port2.
  • C. SD-WAN service rule 4 and port1 or port2.
  • D. SD-WAN service rule 3 and interface HUB1-VPN2.

Answer: B

Explanation:
Traffic steering in Fortinet SD-WAN is based on defined rules and the corresponding outgoing interfaces. The exhibit (not shown here) would indicate that the traffic from the LAN subnet 10.0.1.0/24 to the server
10.2.5.254 is matched by SD-WAN rule 3 and sent out via the HUB1-VPN3 interface.
References:
[FCSS_SDW_AR-7.4 1-0.docx Q2]
FortiOS 7.4 SD-WAN Concept Guide - Rule Matching


NEW QUESTION # 54
Refer to the exhibits.

You use FortiManager to manage the branch devices and configure the SD-WAN template. You have configured direct internet access (DIA) for the IT department users. Now. you must configure secure internet access (SIA) for all local LAN users and have set the firewall policies as shown in the second exhibit.
Then, when you use the install wizard to install the configuration and the policy package on the branch devices, FortiManager reports an error as shown in the third exhibit.
Which statement describes why FortiManager could not install the configuration on the branches?

  • A. You cannot install firewall policies that reference an SD-WAN member.
  • B. You cannot install SIA and DIA rules on the same device.
  • C. You cannot install firewall policies that reference an SD-WAN zone.
  • D. You must direct SIA traffic to a VPN tunnel.

Answer: A

Explanation:
FortiManager enforces a strict distinction:
"Firewall policies must reference SD-WAN zones, not individual SD-WAN members, when used in conjunction with SD-WAN templates. Attempting to install a policy that references a specific member (interface) will result in a deployment error, as member-level targeting is not supported in SD-WAN policy abstraction. This enforces centralized policy consistency and proper SD-WAN operation." Ensuring policies target zones allows FortiGate to dynamically select the optimal member.


NEW QUESTION # 55
Refer to the exhibit.

The administrator configured the SD-WAN rule ID 4 with two members (port1 and port2) and strategy lowest cost (SLA).
What are the two characteristics of the session shown in the exhibit? (Choose two.)

  • A. FortiGate steered this flow according to the application detected and the outgoing interface is port3.
  • B. FortiGate will never re-evaluate this session.
  • C. FortiGate steered this flow according to an SD-WAN rule 4.
  • D. FortiGate will re-evaluate this session if the outgoing interface goes down.

Answer: C,D

Explanation:
The line sdwan_mbr_seq=1 sdwan_service_id=4 indicates that this session is part of an SD-WAN rule.
sdwan_service_id=4 confirms that the session is being handled by SD-WAN rule ID 4. This directly links the flow to the SD-WAN configuration.
The line no_offload_reason: redir-to-ips denied-by-nturbo shows that the session is not offloaded to the NPU (Network Processing Unit) and is being processed by the main CPU. A session that is not offloaded can be re- evaluated. If the outgoing interface (the one currently being used) goes down, the FortiGate will re-evaluate the session against the SD-WAN rules to find a new active member to steer the traffic through. This is a fundamental behavior of SD-WAN, which ensures network resilience.


NEW QUESTION # 56
When a customer delegate the installation and management of its SD-WAN infrastructure to an MSSP, the MSSP usually keeps the hub within its infrastructure for ease of management and to share costly resources.
In which two situations will the MSSP install the hub in customer premises? (Choose two.)

  • A. The administrator expects a large volume of traffic between the branches.
  • B. The customer requires SIA with centralized breakout.
  • C. The customer expects a large amount of VoIP traffic.
  • D. The majority of the branch traffic is directed to a corporate data center.

Answer: A,D


NEW QUESTION # 57
(Refer to the exhibit.

Which statement correctly describes the role of the ADVPN device in handling traffic? Choose one answer.)

  • A. This device is a hub, and two spokes, 192.2.0.1 and 10.0.3.101, established a shortcut.
  • B. This device is a hub that has received a shortcut query from a spoke and has forwarded it to another spoke.
  • C. This device is a spoke that has received a shortcut query from a remote hub.
  • D. This device is a spoke that has received a direct shortcut query from a remote spoke.

Answer: B

Explanation:
The log messages shown in the exhibit include the following key indicators:
* processing notify type SHORTCUT_QUERY
* shortcut-query received from 192.2.0.1
* local-nat=yes, peer-nat=no
* NAT hole punching for peer at 192.2.0.1:4500
In the FCSS SD-WAN 7.6 ADVPN workflow, shortcut queries are always initiated by spokes, not hubs.
A spoke sends a shortcut query to its hub when it detects traffic destined for another spoke. The hub's role is to receive this shortcut query and forward the discovery information toward the destination spoke, enabling the two spokes to build a direct shortcut tunnel.
The device name in the log (HUB1-VPN1) and the presence of NAT hole punching coordination clearly indicate that this device is acting as a hub, not a spoke. Hubs do not form shortcuts themselves; instead, they facilitate shortcut establishment between spokes by relaying discovery and negotiation information.
Option A is incorrect because a spoke does not receive shortcut queries from other spokes directly.
Option B is incorrect because the log does not indicate that the shortcut has already been established; it shows the query and coordination phase, not completion.
Option D is incorrect because hubs do not initiate shortcut queries toward spokes.
Therefore, the correct description is that this device is a hub that has received a shortcut query from a spoke and has forwarded it to another spoke, which corresponds to option C.


NEW QUESTION # 58
(Refer to the exhibit.

The event log on a FortiGate device is shown.
Based on the output shown in the exhibit, what can you conclude about the tunnels on this device? (Choose one answer))

  • A. The voice traffic is steered through the VPN tunnel HUB1-VPN3.
  • B. There is one shortcut tunnel built from the master tunnel VPN4.
  • C. The VPN tunnel HUB1-VPN1_0 is a shortcut tunnel.
  • D. The master tunnel HUB2-VPN3 cannot accept Auto-Discovery VPN (ADVPN) shortcuts.

Answer: C

Explanation:
* In the exhibit, the IPsec tunnel statistics event log entries include the field advpnsc.
* Fortinet documents that advpnsc identifies whether the VPN event is based on an ADVPN shortcut:
* advpnsc=1 # the tunnel is an ADVPN shortcut
* advpnsc=0 # not an ADVPN shortcut (Fortinet Documentation Library)
* In the shown logs, the tunnel vpntunnel="HUB1-VPN1_0" has advpnsc=1, which means HUB1- VPN1_0 is an ADVPN shortcut tunnel. (Fortinet Documentation Library)
* The other tunnels shown (for example VPN4_0 and HUB2-VPN3) have advpnsc=0, which only indicates no shortcut is identified for those log entries-it does not prove they "cannot accept" shortcuts, only that the specific event is not a shortcut. (Fortinet Documentation Library)


NEW QUESTION # 59
Which two statements correctly describe what happens when traffic matches the implicit SD-WAN rule?
(Choose two.)

  • A. The traffic is distributed, regardless of weight, through all available static routes.
  • B. Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.
  • C. The session information output displays no SD-WAN service id.
  • D. Traffic does not match any of the entries in the policy route table.
  • E. FortiGate flags the session with may_dirty and vwl_def ault.

Answer: C,D


NEW QUESTION # 60
Refer to the exhibit.

The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate device that supports hardware offloading.
Based on the information shown in the exhibits, which two conclusions can you draw? (Choose two.)

  • A. The original direction of the symmetric traffic flows from port3 to port2.
  • B. The auxiliary session can be offloaded to hardware.
  • C. By default, FortiGate offloads symmetric and asymmetric flows.
  • D. The reply direction of the asymmetric traffic flows from port2 to port3.

Answer: A,D

Explanation:
The session details show the symmetric flow's original direction as port3 # port2.
The asymmetric flow's reply direction is listed as port2 # port3.


NEW QUESTION # 61
(Refer to the exhibit.

Based on the output shown in the exhibit, what can you conclude about the device role and how it handles health checks? Choose one answer.)

  • A. The device is a hub and it receives health-check measures for the tunnels of a spoke.
  • B. The device is a spoke and it provides embedded health-check measures for each tunnel to the hub.
  • C. The device is a spoke and it receives health-check measures for the tunnels of another spoke.
  • D. The device is a hub and it receives embedded health-check measures for each tunnel from the spoke.

Answer: B


NEW QUESTION # 62
Which statement describes FortiGate behavior when you reference a zone in a static route?

  • A. FoftiGate installs ECMP static routes for the first two members of the zone.
  • B. FortiGate routes the traffic through the best performing member of the zone.
  • C. FortiGate installs a static route for each member in the zone.
  • D. FortiGate ignores the static routes defined through members referenced in the zone.

Answer: C

Explanation:
When referencing a zone in a static route, FortiGate's behavior is described as:
"Referencing a zone in a static route causes FortiGate to install a static route for each member interface of the zone. This enables ECMP (Equal-Cost Multi-Path) and load balancing where supported and ensures that traffic can be steered over any valid zone member according to SD-WAN rules or standard routing." This mechanism is fundamental to Fortinet's implementation of SD-WAN and simplifies large, multi- interface deployments.
References:
[FCSS_SDW_AR-7.4 1-0.docx Q21]
FortiOS 7.4 Routing Guide, "Zone-based Routing and ECMP Behavior"


NEW QUESTION # 63
(You are using the FortiManager SD-WAN monitor menus to check the status of an SD-WAN topology.
When you place the mouse next to branch1_fgt, you receive the output shown in the exhibit.

Which two conclusions can you draw from the output shown in the exhibit? Choose two answers.)

  • A. Three spokes have tunnels that are out of SLA.
  • B. branch3_fgt is configured with three SD-WAN overlay tunnels and one is down.
  • C. branch1_fgt is configured with six SD-WAN overlay tunnels and three are down.
  • D. The template Corp-SOT defines a dual-hub topology.

Answer: A,B


NEW QUESTION # 64
(You are configuring SD-WAN to load balance network traffic and you want to take into account the link quality.
Which two facts should you consider? Choose two answers.)

  • A. You can select the best quality strategy and allow SD-WAN load balancing.
  • B. You can select the lowest cost service level agreement (SLA) strategy and allow SD-WAN load balancing.
  • C. When applicable, FortiGate load balances the traffic through all members that meet the SLA target.
  • D. The best quality strategy supports only the round-robin hash mode.

Answer: B,C

Explanation:
When SD-WAN load balancing is required with link quality awareness, FortiOS relies on SLA-based strategies. These strategies evaluate link performance using performance SLAs (latency, jitter, packet loss, MOS) and then make forwarding decisions accordingly.
Option A is correct.
In FortiOS 7.6, when an SLA-based SD-WAN rule has load balancing enabled, FortiGate distributes traffic only across the members that meet the SLA targets. Any member that is out of SLA is excluded from load balancing. This behavior ensures that traffic is not forwarded over degraded links while still allowing load distribution across healthy paths.
Option C is correct.
The lowest cost (SLA) strategy is an SLA-based strategy that considers link quality while also allowing SD- WAN load balancing. When multiple members meet the SLA requirements and have equal cost, FortiGate can load balance traffic across them using the configured hash mode. This makes the lowest cost SLA strategy suitable when both link quality and load balancing are required.
Why the other options are incorrect:
* Option B is incorrect because the best quality strategy is designed to select the single best-performing link based on SLA metrics. It does not support SD-WAN load balancing across multiple links.
* Option D is incorrect because the best quality strategy does not support load balancing at all, so the statement about round-robin hash mode is invalid.
Therefore, the two correct facts to consider are A and C.


NEW QUESTION # 65
(Refer to the exhibits.

The SD-WAN overlay template advanced settings and the underlay and network advertisement settings are shown. These are the configurations for the secondary hub of a dual-hub SD-WAN topology created with the FortiManager SD-WAN overlay orchestrator.
Which two conclusions can you draw from the information shown in the exhibits? Choose two answers.)

  • A. FortiManager will create an overlay tunnel on the port2 interface.
  • B. FortiManager will define port5 as a BGP neighbor.
  • C. FortiManager will define port2 as a BGP neighbor.
  • D. FortiManager will create an overlay tunnel on the port1 interface.

Answer: A,D

Explanation:
From the Underlay and network advertisement configuration exhibit for the Secondary HUB:
* Under Underlay, the template explicitly lists:
* WAN Underlay 1 = port1
* WAN Underlay 2 = port2
In FortiManager SD-WAN Overlay Orchestrator, underlay interfaces selected for a hub are the transports used to build the overlay IPsec tunnels (one overlay per underlay, per peer as defined by the template).
Because both port1 and port2 are configured as underlays, FortiManager will build overlay tunnels over both underlay links. That supports:
* Option C (overlay tunnel on port1)
* Option B (overlay tunnel on port2)
For the BGP neighbor options:
* The Network Advertisement section shows Interface 1 = port5, which indicates a LAN/internal interface whose connected or static networks may be advertised into the overlay routing domain. This does not make port5 a BGP neighbor interface; it is the interface whose routes are being advertised.
* The template indicates Dynamic BGP is enabled. In Overlay Orchestrator designs, BGP neighbor relationships are formed across the overlay tunnel interfaces / overlay endpoints, not directly on the raw underlay interfaces (port1/port2) and not on the advertised LAN interface (port5). Therefore, options A and D are not valid conclusions from what is shown.
So, the two correct conclusions are B and C.


NEW QUESTION # 66

Refer to the exhibit.
You want to configure SD-WAN on a network as shown in the exhibit.
The network contains many FortiGate devices. Some are used as NGFW, and some are installed with extensions such as FortiSwitch. FortiAP. or Forti Ex tender.
What should you consider when planning your deployment?

  • A. You can build an SD-WAN topology that includes all devices. The hubs must be devices without extensions.
  • B. You can build an SD-WAN topology that includes all devices. The hubs can be FortiGate devices with Forti Extender.
  • C. You must use FortiManager to manage your SD-WAN topology.
  • D. You must build multiple SD-WAN topologies. Each topology must contain only one type of extension.

Answer: A

Explanation:
In Fortinet SD-WAN, hubs should not have extensions like FortiSwitch, FortiAP, or FortiExtender installed, as these can affect hub functionality and scalability. While all device types can be included in the topology, the hubs must be "clean" FortiGate devices without such extensions to ensure proper ADVPN and overlay management.
References:
[FCSS_SDW_AR-7.4 1-0.docx Q3]
Fortinet SD-WAN Reference Architecture Guide 7.4 - Hub requirements


NEW QUESTION # 67
SD-WAN interacts with many other FortiGate features. Some of them are required to allow SD-WAN to steer the traffic.
Which three configuration elements that you must configure before FortiGate can steer traffic according to SD-WAN rules? (Choose three.)

  • A. Firewall policies
  • B. Security profiles
  • C. Traffic shaping
  • D. Routing
  • E. Interfaces

Answer: A,D,E

Explanation:
Before FortiGate can steer traffic according to SD-WAN rules, certain configuration elements must be present. The guide states:
"SD-WAN is not a standalone feature and interacts with several fundamental FortiGate configurations.
Specifically, you must: (1) Define the interfaces (physical, VLAN, or IPsec) that will act as SD-WAN members, (2) Create firewall policies to allow traffic to be steered by SD-WAN, and (3) Set up routing so that traffic has valid routes via SD-WAN members. Without these, SD-WAN rules will not be able to match or steer any traffic." Security profiles and traffic shaping are not mandatory for basic SD-WAN steering but can be layered on for enhanced security and QoS once foundational elements are present.
References:
[FCSS_SDW_AR-7.4 1-0.docx Q16]
FortiOS 7.4 SD-WAN Concept Guide, "Prerequisite Configuration Elements for SD-WAN Steering


NEW QUESTION # 68
Refer to the exhibit.

The administrator used the SD-WAN overlay template to prepare an IPsec tunnels configuration for a hub- and-spoke SD-WAN topology. The exhibit shows the FortiManager installation preview for one FortiGate device.
Based on the exhibit, which statement best describes the configuration applied to the FortiGate device?

  • A. It is a spoke device that establishes dynamic IPsec tunnels to the hub It can send ADVPN shortcut requests.
  • B. It is a hub device. It will automatically discover the spoke devices and add them to the SD-WAN topology.
  • C. It is a hub device. It can send ADVPN shortcut offers.
  • D. It is a spoke device that establishes dynamic IPsec tunnels to the hub. The local subnet range is
    10.10.128.0/23.

Answer: C

Explanation:
The FortiManager SD-WAN overlay template preview, as described in the document, indicates:
"When the device is acting as a hub, the configuration enables the sending of ADVPN shortcut offers to spokes. This means the hub can facilitate on-demand dynamic shortcut tunnel creation between spokes, improving performance for branch-to-branch communication by bypassing the hub for inter-branch traffic after initial discovery." Such a role is critical in scalable ADVPN topologies, enabling hub devices to optimize overlays dynamically.


NEW QUESTION # 69
When you use the command diagnose sys session list, how do you identify the sessions that correspond to traffic steered according to SD-WAN rules?

  • A. You identify sessions steered according to SD-WAN rules with the data vwl_mbr_seq.
  • B. You cannot identify SD-WAN sessions. You must use the sdwar. session filter.
  • C. You identify sessions steered according to SD-WAN rules with the data 3dwan_service_id.
  • D. You identify sessions steered according to SD-WAN rules with the flag vwl.

Answer: C

Explanation:
When using the diagnose sys session list command, SD-WAN-specific session steering is indicated by the presence of the sdwan_service_id field in the session data. This identifier ties the session directly to a specific SD-WAN rule or service. As noted in the Fortinet documentation: "Sessions that are handled according to SD- WAN rules will include a service ID tag (sdwan_service_id) in their session listing. This allows administrators to correlate live sessions with SD-WAN policy matches for troubleshooting and visibility." This is a crucial diagnostic tool, as it distinguishes between traffic managed by traditional routing and that explicitly controlled by SD-WAN steering logic, aiding in operational insight and troubleshooting.
References:
[FCSS_SDW_AR-7.4 1-0.docx Q15]
FortiOS 7.4 CLI Reference, "diagnose sys session list: SD-WAN Service ID Tagging" SD-WAN 7.4 Concept Guide, Section: "Session Identification for SD-WAN Traffic"


NEW QUESTION # 70
......

New (2026) Fortinet NSE6_SDW_AD-7.6 Exam Dumps: https://actualtests.testinsides.top/NSE6_SDW_AD-7.6-dumps-review.html