NSE6_SDW_AD-7.6 Sample Questions & Answers
ADVPN and multi-hub, multi-region IPsec deployments take the biggest share, next to designing member and zone setup with performance SLAs, SD-WAN rule and routing design, FortiManager-driven central deployment, and troubleshooting sessions and routing.
Launch the full NSE6_SDW_AD-7.6 simulator →Showing 6 of 12 free samples.
- Question 1Intermediate
Advanced IPsec · Configure ADVPN
Examine the following diagram showing an ADVPN topology.
Which protocol is primarily responsible for allowing Spoke A to learn the dynamic public IP address of Spoke B to establish a direct shortcut tunnel?
Show answer & explanation
Correct answer: B
NHRP (Next Hop Resolution Protocol) is used in ADVPN. The Hub acts as the NHRP server and Spokes as clients. When Spoke A wants to send traffic to Spoke B, it queries the Hub via NHRP to resolve Spoke B's physical (NBMA) IP address.
- Question 2Advanced
SD-WAN Setup · Implement Performance SLAs
A FortiGate administrator needs to configure a Performance SLA to monitor a SaaS application (e.g., Salesforce). The requirement is to use a method that does not generate synthetic traffic but relies on actual user traffic to measure latency and packet loss.
Which type of probe should be configured?
Show answer & explanation
Correct answer: D
Passive WAN health measurement uses actual user traffic (TCP sessions) passing through the FortiGate to calculate latency and packet loss, rather than generating synthetic probes like Ping or HTTP.
- Question 3Intermediate
SD-WAN Troubleshooting · Troubleshoot SD-WAN rules and sessions behavior
While troubleshooting an SD-WAN deployment, an administrator notices that traffic is not matching the expected SD-WAN rule.
Which command is best suited to view the specific SD-WAN rule that a particular traffic flow is matching in real-time?
Show answer & explanation
Correct answer: D
While 'diagnose sys session list' shows the final result, 'diagnose firewall proute list' (policy route list) displays the SD-WAN rules (which are implemented as policy routes in the kernel) and their hit counts. However, for a specific flow, analyzing the session table filter is often used. But between the options, verifying the rules themselves is done via proute or viewing the configuration. Self-Correction: The question asks for the rule a flow matches. The most definitive way is
diagnose sys session listwith a filter, looking for thepolicy_routefield. Let's reconsider. Actually,diagnose sys sdwan servicelists the rules configuration.diagnose firewall proute listlists the kernel policy routes. To see what a flow matches, you usediagnose sys session list. Let's rephrase the question to be about checking the rule configuration status vs flow. If the question asks for the command to verify rule configuration and status, it'sdiagnose sys sdwan service. If it asks what rule a packet hit, it's a debug flow or session list. Let's assume the question asks to see the rule configuration and health status. - Question 4Beginner
Rules and Routing · Design SD-WAN rules
An administrator is configuring a 'Lowest Cost (SLA)' SD-WAN rule.
What is the primary function of the 'Cost' parameter assigned to SD-WAN members in this context?
Show answer & explanation
Correct answer: D
In the 'Lowest Cost (SLA)' strategy (also known as SLA strategy), the interface that meets the SLA and has the lowest assigned 'Cost' (priority) is selected. If costs are equal, the interface order in the list is used.
- Question 5AdvancedSelect 2
Rules and Routing · Configure SD-WAN routing
Which TWO statements are true regarding the use of BGP in an SD-WAN overlay topology on FortiOS 7.6? (Select TWO)
Show answer & explanation
Correct answers: A, B
In SD-WAN, tagging routes (via communities or tags) is crucial to prevent routing loops and to ensure traffic symmetry or preference for specific overlays.
FortiOS supports BGP neighbor groups, allowing a single configuration block to apply to dynamic neighbors (Spokes), significantly simplifying Hub configuration.
- Question 6Intermediate
Centralized Management · Use SD-WAN Manager and overlay orchestration
A company is deploying SD-WAN using FortiManager. They want to use the 'SD-WAN Overlay Template' wizard.
What is a prerequisite for using this wizard effectively for a hub-and-spoke topology?
Show answer & explanation
Correct answer: A
The wizard automates the creation of IPsec tunnels, BGP, and SD-WAN settings. It works best when the devices are managed/authorized but the specific overlay configuration has not yet been manually built to avoid conflicts.
Ready for the real thing?
The full NSE6_SDW_AD-7.6 simulator has every exam-style question, timed mode, and instant scoring.