FCSS-SDW-AR-7.4 Fortinet FCSS - SD-WAN 7.4 Architect Practice Questions
Prepare for FCSS-SDW-AR-7.4 with more than an answer.
- Exam fee
- $200 USD
- Time limit
- 75 minutes
- Questions on the exam
- 38
- Passing score
- Pass/Fail (scale Pass/Fail)
- Level
- Solution Specialist
- Valid for
- 2 years
Domains covered on the exam 5
- SD-WAN Configuration25%
- Rules and Routing25%
- Centralized Management20%
- Advanced IPsec20%
- SD-WAN Troubleshooting10%
- 1
The
diagnose firewall proute listcommand is used to display the policy routing table on a FortiGate. When SD-WAN is enabled, this output will show routes created by which component?Show answer details
Correct answer: B
The FortiOS SD-WAN feature integrates with the policy routing table. Each configured SD-WAN rule (service) dynamically creates corresponding entries in the policy route table. The
diagnose firewall proute listcommand is a crucial tool for troubleshooting as it shows exactly how the SD-WAN rules have been translated into routable decisions. - 2
True or False: In a Fortinet ADVPN configuration, a firewall policy with the action
IPsecis required on the hub to allow traffic to pass between two spokes before a shortcut is established.Show answer details
Correct answer: B
This is correct. The traffic from one spoke arrives at the hub, is decrypted, and then needs to be routed and forwarded to the other spoke. This forwarding action requires a normal
Acceptpolicy (Source Interface: ipsec_tunnel, Destination Interface: ipsec_tunnel). AnIPsecaction policy is not used for this traffic flow. - 3
Which three of the following are valid path selection strategies for an SD-WAN rule in FortiOS 7.4? (Select THREE)
Show answer details
Correct answer: C, D, E
This strategy, often referred to as 'Load Balance', distributes sessions across multiple links based on configured algorithms like volume, sessions, or spillover to maximize bandwidth utilization.
Lowest Cost is a valid strategy that uses the member interfaces according to a preferred order, failing over to the next in the list if the preferred one fails or goes out of SLA.
Best Quality is a valid strategy that selects the best-performing link based on the criteria in a chosen Performance SLA.
- 4
An administrator is using FortiManager to push a configuration update to a branch FortiGate. After the installation, the administrator notices that some local settings on the branch device, which were configured directly on the FortiGate GUI, have been overwritten. What is the most likely reason for this behavior?
Show answer details
Correct answer: B
FortiManager's default behavior can be configured at the ADOM level. If 'Allow FortiManager Overwrite' (or a similar setting depending on the version) is enabled, when FortiManager pushes its configuration, it can overwrite any settings on the end device, including those it does not explicitly manage. To preserve local changes, this should be disabled, forcing FortiManager to only manage the objects defined within its database.
- 5
The diagram below shows a basic hub-and-spoke ADVPN topology. A user at Spoke A (10.10.1.0/24) initiates a file transfer to a server at Spoke B (10.20.1.0/24). What is the correct sequence of events for establishing a direct ADVPN shortcut?
graph TD subgraph Internet Hub[Hub FortiGate] end SpokeA[Spoke A 10.10.1.0/24] -- IPsec Tunnel --> Hub SpokeB[Spoke B 10.20.1.0/24] -- IPsec Tunnel --> Hub SpokeA -.-> SpokeB style SpokeA-.-> stroke-dasharray: 5 5, color:greenShow answer details
Correct answer: C
This is the correct sequence. The initial packet(s) trigger the process by flowing through the hub. The hub forwards this traffic and also sends an IKE information message to the initiator (Spoke A) containing the peer information for Spoke B. Spoke A then initiates the direct IKE negotiation with Spoke B to build the on-demand shortcut tunnel.
- 6
A financial services company is deploying a dual-region SD-WAN architecture using FortiManager. The design requires that each region (NA and EU) has its own hub, and spokes within a region must establish ADVPN shortcuts. Additionally, spokes in NA must be able to establish shortcuts directly with spokes in EU. Which two FortiManager settings are essential to enable this inter-region ADVPN functionality? (Select TWO)
Show answer details
Correct answer: A, E
Enabling auto-discovery sender and receiver roles on the IPsec tunnel connecting the two hubs allows them to forward IKE messages related to shortcut negotiation on behalf of their respective spokes. This is the core mechanism that facilitates inter-region shortcuts.
Establishing a BGP neighborship between the regional hubs is crucial for them to exchange spoke routing information. This allows a hub in one region to learn about the spokes connected to the hub in the other region, which is a prerequisite for shortcut negotiation.
- 7
A network architect is using a FortiManager SD-WAN template to deploy configurations to over 200 retail branches. Each branch has a unique local subnet (e.g., 10.101.X.0/24, 10.102.X.0/24). To simplify firewall policy creation within the template, the architect needs to define a single object that represents the unique local subnet of any branch the template is applied to. Which FortiManager feature should be used for this purpose?
Show answer details
Correct answer: D
A metadata variable (e.g.,
$(lan_subnet)) is the correct feature. The architect can define this variable in the template's address object and then assign the specific subnet value for each branch in the device manager settings. FortiManager will substitute the correct value during deployment. - 8
During an SD-WAN deployment, a spoke FortiGate fails to establish an IPsec tunnel with the hub. The administrator runs the command
diagnose debug application iked -1and observes the error message "no proposal chosen" in the output. What is the most likely cause of this issue?Show answer details
Correct answer: A
The "no proposal chosen" error message specifically indicates that the IKE peers (hub and spoke) could not agree on a common set of security parameters during either Phase 1 or Phase 2 negotiation. This is caused by a mismatch in the configured encryption algorithms, authentication methods, Diffie-Hellman groups, or key lifetimes.
- 9
An organization has configured an SD-WAN rule to steer Microsoft 365 traffic. The path selection strategy is set to 'Best Quality', which considers three member interfaces: MPLS, DIA-1, and DIA-2. A Performance SLA is configured to monitor latency to
office.com. During a network event, the MPLS link experiences high latency, violating the SLA. DIA-1 and DIA-2 are both within SLA thresholds. How will the FortiGate handle new Microsoft 365 sessions?Show answer details
Correct answer: D
When using the 'Best Quality' strategy, FortiGate first disqualifies any member that violates the SLA (in this case, MPLS). From the remaining members that are within SLA (DIA-1 and DIA-2), it will select the one with the best performance based on the SLA criteria (latency). If multiple links are viable, it may load-balance or prefer the best one, but it will only use the links that meet the SLA.
- 10
True or False: When using FortiManager to manage a large-scale SD-WAN deployment, the SD-WAN Overlay Template can be used to automatically generate the required BGP neighbor configurations between the hub and all spokes.
Show answer details
Correct answer: A
True. The SD-WAN Overlay Template in FortiManager is a powerful automation tool. It can be configured to not only create the IPsec tunnels but also to automatically generate the corresponding BGP configurations for the hub and spokes, significantly simplifying the deployment of dynamic routing across the overlay.
