NSE6_SDW_AD-7.6 Sample Questions

NSE6_SDW_AD-7.6 Sample Questions & Answers

ADVPN and multi-hub, multi-region IPsec deployments take the biggest share, next to designing member and zone setup with performance SLAs, SD-WAN rule and routing design, FortiManager-driven central deployment, and troubleshooting sessions and routing.

Launch the full NSE6_SDW_AD-7.6 simulator →

Showing 6 of 12 free samples.

  1. Question 1Intermediate

    Advanced IPsec · Configure ADVPN

    Examine the following diagram showing an ADVPN topology.

    Which protocol is primarily responsible for allowing Spoke A to learn the dynamic public IP address of Spoke B to establish a direct shortcut tunnel?

    Show answer & explanation

    Correct answer: B

    NHRP (Next Hop Resolution Protocol) is used in ADVPN. The Hub acts as the NHRP server and Spokes as clients. When Spoke A wants to send traffic to Spoke B, it queries the Hub via NHRP to resolve Spoke B's physical (NBMA) IP address.

  2. Question 2Advanced

    SD-WAN Setup · Implement Performance SLAs

    A FortiGate administrator needs to configure a Performance SLA to monitor a SaaS application (e.g., Salesforce). The requirement is to use a method that does not generate synthetic traffic but relies on actual user traffic to measure latency and packet loss.

    Which type of probe should be configured?

    Show answer & explanation

    Correct answer: D

    Passive WAN health measurement uses actual user traffic (TCP sessions) passing through the FortiGate to calculate latency and packet loss, rather than generating synthetic probes like Ping or HTTP.

  3. Question 3Intermediate

    SD-WAN Troubleshooting · Troubleshoot SD-WAN rules and sessions behavior

    While troubleshooting an SD-WAN deployment, an administrator notices that traffic is not matching the expected SD-WAN rule.

    Which command is best suited to view the specific SD-WAN rule that a particular traffic flow is matching in real-time?

    Show answer & explanation

    Correct answer: D

    While 'diagnose sys session list' shows the final result, 'diagnose firewall proute list' (policy route list) displays the SD-WAN rules (which are implemented as policy routes in the kernel) and their hit counts. However, for a specific flow, analyzing the session table filter is often used. But between the options, verifying the rules themselves is done via proute or viewing the configuration. Self-Correction: The question asks for the rule a flow matches. The most definitive way is diagnose sys session list with a filter, looking for the policy_route field. Let's reconsider. Actually, diagnose sys sdwan service lists the rules configuration. diagnose firewall proute list lists the kernel policy routes. To see what a flow matches, you use diagnose sys session list. Let's rephrase the question to be about checking the rule configuration status vs flow. If the question asks for the command to verify rule configuration and status, it's diagnose sys sdwan service. If it asks what rule a packet hit, it's a debug flow or session list. Let's assume the question asks to see the rule configuration and health status.

  4. Question 4Beginner

    Rules and Routing · Design SD-WAN rules

    An administrator is configuring a 'Lowest Cost (SLA)' SD-WAN rule.

    What is the primary function of the 'Cost' parameter assigned to SD-WAN members in this context?

    Show answer & explanation

    Correct answer: D

    In the 'Lowest Cost (SLA)' strategy (also known as SLA strategy), the interface that meets the SLA and has the lowest assigned 'Cost' (priority) is selected. If costs are equal, the interface order in the list is used.

  5. Question 5AdvancedSelect 2

    Rules and Routing · Configure SD-WAN routing

    Which TWO statements are true regarding the use of BGP in an SD-WAN overlay topology on FortiOS 7.6? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

    In SD-WAN, tagging routes (via communities or tags) is crucial to prevent routing loops and to ensure traffic symmetry or preference for specific overlays.

    FortiOS supports BGP neighbor groups, allowing a single configuration block to apply to dynamic neighbors (Spokes), significantly simplifying Hub configuration.

  6. Question 6Intermediate

    Centralized Management · Use SD-WAN Manager and overlay orchestration

    A company is deploying SD-WAN using FortiManager. They want to use the 'SD-WAN Overlay Template' wizard.

    What is a prerequisite for using this wizard effectively for a hub-and-spoke topology?

    Show answer & explanation

    Correct answer: A

    The wizard automates the creation of IPsec tunnels, BGP, and SD-WAN settings. It works best when the devices are managed/authorized but the specific overlay configuration has not yet been manually built to avoid conflicts.

Ready for the real thing?

The full NSE6_SDW_AD-7.6 simulator has every exam-style question, timed mode, and instant scoring.