[Q45-Q62] Get 100% Passing Success With True FCSS_SDW_AR-7.6 Exam! [Dec-2025]

Share

Get 100% Passing Success With True FCSS_SDW_AR-7.6 Exam! [Dec-2025]

Fortinet FCSS_SDW_AR-7.6 PDF Questions - Exceptional Practice To FCSS - SD-WAN 7.6 Architect

NEW QUESTION # 45
Refer to the exhibit.

The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths. However, when looking at the spoke routing table, the administrator does not see the prefixes from other spokes and the additional paths Which three settings must the administrator configure inside each BGP neighbor group so spokes can learn the prefixes of other spokes and their additional paths? (Choose three.)

  • A. Enable route-reflector-server
  • B. Set additional-pathto forward
  • C. Enable route-reflector-client.
  • D. Set adv-additional-pathto the number of additional paths to advertise.
  • E. Set additional-pathto send

Answer: C,D,E

Explanation:
The hub must send additional paths to spokes (set additional-path send).
The hub must treat each spoke as a route-reflector client so spoke routes are reflected to other spokes.
The hub must specify how many additional paths to advertise (set adv-additional-path <n>).


NEW QUESTION # 46
Refer to the exhibits, which show the configuration of an SD-WAN rule and the corresponding rule status and routing table.


The administrator wants to understand the expected behavior for traffic matching the SD-WAN rule.
Based on the exhibits, what can the administrator expect for traffic matching the SD-WAN rule?

  • A. The traffic will be routed over HUB1-VPN1.
  • B. The traffic will be routed over HUB1-VPN2
  • C. The traffic will be routed over HUB1-VPN3.
  • D. The traffic will be load balanced across all three overlays

Answer: B

Explanation:
The rule is in SLA mode with two SLAs. From the status, HUB1-VPN2 and HUB1-VPN3 meet the SLA (sla(0x2) and sla(0x3)), while HUB1-VPN1 does not (sla(0x0)). Among members that meet SLA, FortiGate uses the configured order (priority-members 4 5 6) to pick the first eligible one- HUB1-VPN2-so traffic is routed over HUB1-VPN2.


NEW QUESTION # 47
You want FortiGate to use SD-WAN rules to steer local-out traffic.
Which two constraints should you consider? (Choose two.)

  • A. By default, FortiGate uses SD-WAN rules only for local-out traffic that corresponds to pingand traceroute.
  • B. You can steer local-out traffic only with SD-WAN rules that use the manual strategy.
  • C. By default, local-out traffic does not use SD-WAN.
  • D. You must configure each local-out feature individually to use SD-WAN.

Answer: C,D

Explanation:
By default, local-out traffic does not use SD-WAN → FortiGate normally sends local-out traffic (e.g., DNS, NTP, FortiGuard updates) directly through its interfaces without applying SD-WAN rules.
You must configure each local-out feature individually to use SD-WAN → To steer local-out traffic via SD-WAN, you must explicitly configure the desired local-out features (e.g., DNS, FortiGuard, CAPWAP) to use SD-WAN rules.


NEW QUESTION # 48
You configured an SD-WAN rule with the best quality strategy and selected the predefined health check, Default_FortiGuard, to check the link performances against FortiGuard servers.
For the quality criteria, you selected Custom-profile-1.
Which factors does FortiGate use, and in which order. to determine the link that it should use to steer the traffic?

  • A. Latency - Jitter - Packet loss - Bibandwidth - Member configuration order
  • B. Links that meet the SLA targets - Member configuration order - Member local cost
  • C. Latency - Member configuration order - Link cost threshold
  • D. Link quality index - Member configuration order - Link cost threshold

Answer: D

Explanation:
FortiGate determines the member with the best quality using three factors: member configuration order, the link-cost-threshold setting, and the value of the metric measured for the member.


NEW QUESTION # 49
Refer to the exhibits.
Exhibit A

Exhibit B

Exhibit A shows a policy package definition. Exhibit B shows the install log that the administrator received when he tried to install the policy package on FortiGate devices.
Based on the output shown in the exhibits, what can the administrator do to solve the issue?

  • A. Use a metadata variable instead of a dynamic interface to define the firewall policy.
  • B. Policies can refer to only one LAN source interface. Keep only the D-LAN, which is the dynamic LAN interface.
  • C. Dynamic mapping should be done automatically. Review the LAN interface configuration for branch2_fgt.
  • D. Create dynamic mapping for the LAN interface for all devices in the installation target list.

Answer: D


NEW QUESTION # 50
Refer to the exhibit. The exhibit shows the health-check configuration on a FortiGate device used as a spoke. You notice that the hub FortiGate doesn't prioritize the traffic as expected.
Which two configuration elements should you check on the hub? (Choose two.)

  • A. The performance SLA uses the same criteria.
  • B. The performance SLA has the parameter priority-out-slaconfigured.
  • C. The performance SLA is configured with set embedded-measure accept.
  • D. This performance SLA uses the same members.

Answer: A,B

Explanation:
priority-out-sla on the hub - The hub's performance-SLA must define how to prefer/steer traffic when a member is out of SLA; without priority-out-sla, the hub may not reprioritize as you expect.
Same SLA criteria - The hub needs to evaluate links with the same health criteria (e.g., latency with the same threshold) used by the spoke; mismatched criteria lead to different path choices.


NEW QUESTION # 51
The administrator uses the FortiManager SD-WAN overlay template to prepare an SD-WAN deployment. Using information provided through the SD-WAN overlay template wizard, FortiManager creates templates ready to install on the spoke and hub devices.
What are the three templates created by the SD-WAN overlay template for a spoke device?
(Choose three.)

  • A. CLI template
  • B. IPsec tunnel template
  • C. Static route template
  • D. Rules template
  • E. BGP template

Answer: A,B,E

Explanation:
CLI template → Contains device-specific parameters (like local interface IPs).
BGP template → Configures dynamic routing for overlay tunnels.
IPsec tunnel template → Builds the IPsec VPN tunnels from the spoke to the hubs.


NEW QUESTION # 52
Refer to the exhibits. The first exhibit shows the SD-WAN zone HUB1 and SD-WAN member configuration from an SD-WAN template, and the second exhibit shows the output of command diagnose sys sdwan membercollected on a FortiGate device.
Which statement best describes what the diagnose output shows?


  • A. The diagnose output was collected on the device branch2_fgt.
  • B. The diagnose output shows that HUB1-VPN1 and all HUBx-VPNy members are dead.
  • C. The diagnose output does not correspond to a device configured with the SD-WAN template shown in the exhibit.
  • D. The diagnose output was collected on the device branch1_fgt.

Answer: D

Explanation:
The diagnose output lists SD-WAN members 4(HUB1-VPN1), 5(HUB1-VPN2), 7(HUB2-VPN1),
8(HUB2-VPN2), and 9(HUB2-VPN3). It does not include member 6 (HUB1-VPN3). From the template, HUB1-VPN3 is installed only on branch2_fgt and branch3_fgt - not on branch1_fgt.
Therefore, the output must be from branch1_fgt.


NEW QUESTION # 53
Refer to the exhibit. The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate device that supports hardware offloading.
Based on the information shown in the exhibits, which two conclusions can you draw? (Choose two.)

  • A. By default, FortiGate offloads symmetric and asymmetric flows.
  • B. The original direction of the symmetric traffic flows from port3 to port2.
  • C. The auxiliary session can be offloaded to hardware.
  • D. The reply direction of the asymmetric traffic flows from port2 to port3.

Answer: C,D

Explanation:
The session output shows reflect info: dev=7->6/6->7. From the netlink list, index 6 = port2 and 7
= port3, so the reply direction of the asymmetric (auxiliary) session is port2 → port3.
The auxiliary session has npu info ... offload=8/8 (non-zero), indicating it can be offloaded to hardware.


NEW QUESTION # 54
Refer to the exhibit. Which statement best describe the role of the ADVPN device in handling traffic?

  • A. This is a spoke that has received a shortcut query from a remote hub.
  • B. This is a hub that has received a shortcut query from a spoke and has forwarded it to another spoke.
  • C. This is a spoke that has received a direct shortcut query from a remote spoke.
  • D. This is a hub, and two spokes, 192.2.0.1and 10.0.3.101, establish a shortcut.

Answer: B

Explanation:


NEW QUESTION # 55
Refer to the exhibit. Two hub-and-spoke groups are connected through redundant site-to-site IPsec VPNs between Hub 1 and Hub 2.
Which two configuration settings are required for the spoke A1 to establish an ADVPN shortcut with the spoke B2? (Choose two.)

  • A. On hubs, auto-discovery-forwarder must be enabled on the IPsec VPNs to spokes.
  • B. On hubs, auto-discovery-forwarder must be enabled on the IPsec VPNs to hubs.
  • C. On hubs, auto-discovery-receiver must be enabled on the IPsec VPNs to spokes.
  • D. On hubs, auto-discovery-sender must be enabled on the IPsec VPNs to spokes.

Answer: B,D

Explanation:


NEW QUESTION # 56
Refer to the exhibits. The exhibits show an SD-WAN event log, the member status, and the SD- WAN rule configuration.
Which two conclusions can you draw from the information shown? (Choose two.)


  • A. FortiGate updated the outgoing interface list on the rule so it prefers port2.
  • B. Port2 has a lower latency than port1.
  • C. The administrator configured the SD-WAN rule ID 1 with the default strategy mode.
  • D. The administrator configured the service ID 1 with the highest priority member for port2.

Answer: A,B

Explanation:
The SD-WAN rule (config service edit 1) is configured with set mode priority. This means the rule selects the best interface based on a defined performance metric, as opposed to a simple static priority or SLA. The event log (image_41cfb5.png) shows Metric latency and Message Service prioritized by performance metric will be redirected in sequence order. This indicates that the rule is using latency to determine the preferred member. Given that the log message is about a change, and the most logical reason for a change in a priority mode is that a different member is now the best performer, it implies that the latency on port2 has become lower than that on port1.
The log message Service prioritized by performance metric will be redirected in sequence order confirms that FortiGate is changing the member being used for this service. Because the mode is priority, FortiGate dynamically selects the member that currently meets the best performance criteria, which in this case is latency. The log implies a new member has been selected as the most optimal, and with the default configuration, the members are sorted based on their performance, so the outgoing interface list is effectively updated to prefer the new best- performing member (port2).


NEW QUESTION # 57
Refer to the exhibit. You configure SD-WAN on a standalone FortiGate device. You want to create an SD-WAN rule that steers Facebook and Linkedin traffic through the less costly internet link. The FortiGate GUI page appears as shown in the exhibit.
What should you do to set Facebook and LinkedIn as destinations?

  • A. In the Internet service field, select Facebook and LinkedIn.
  • B. Install a license to allow applications as destinations of SD-WAN rules.
  • C. You cannot configure applications as destinations of an SD-WAN rule on a standalone FortiGate device.
  • D. Enable the applications as destinations of the SD-WAN rule feature visibility.

Answer: A

Explanation:
In an SD-WAN rule, you can steer application traffic by using Internet Service Database (ISDB) entries. Facebook and LinkedIn are predefined ISDB objects in FortiGate, so the correct way is to select them in the Internet service field under Destination. This ensures that all traffic to these applications is matched and routed through the chosen (less costly) link.


NEW QUESTION # 58
Refer to the exhibits. The exhibits show the SD-WAN zone configuration of an SD-WAN template prepared on FortiManager and the policy package configuration.
When the administrator tries to install the configuration changes, FortiManager fails to commit.
What should the administrator do to fix the issue?

  • A. Configure both HUB1-VPN1 and HUB1-VPN2 as the destination of policy 3.
  • B. Configure branch1_fgt as the installation target for policy 3.
  • C. Configure a normalized interface for the IPsec tunnel HUB1-VPN1.
  • D. Configure HUB1 as the destination of policy 3.

Answer: D

Explanation:
Policy 3 points traffic To = HUB1-VPN1, which is an SD-WAN member interface. In SD-WAN you must reference the SD-WAN zone (the logical interface) in policies, not its member tunnels.
Change the policy's To interface to the zone HUB1, and the install will succeed.


NEW QUESTION # 59
Refer to the exhibit. The exhibit shows output of the command diagnose sys sdwan service4collected on a FortiGate device The administrator wants to know through which interface FortiGate will steer traffic from local users on subnet 10 0.1.0/255.255.255.192 and with a destination of the social media application Facebook.
Based on the exhibits, which two statements are correct? (Choose two.)

  • A. There is no service defined for the Facebook application, so FortiGate appliesservice rule 3 and directs the traffic to headquarters.
  • B. When FortiGate cannot recognize the application of the flow, it load balances the traffic through the tunnels HQ_T1, HQ_T2, HQ_T3.
  • C. When FortiGate cannot recognize the application of the flow, it steers the traffic through the preferred member of rule 3, HQ_T1.
  • D. FortiGate steers traffic for social media applications according to the service rule 2 and steers traffic through port2.

Answer: B,D

Explanation:
Service rule 2 includes Social.Media (0,23), which matches Facebook, and only port2 is selected and alive.
If the application is not identified, service rule 3 (with mode=round-robin) distributes traffic across HQ_T1, HQ_T2, and HQ_T3.


NEW QUESTION # 60
You are planning a large SD-WAN deployment with approximately 1000 spokes and want to allow ADVPN between the spokes. Some remote sites use FortiSASE to connect to the company's SD- WAN hub. Which overlay routing configuration should you use?

  • A. BGP on loopback with IPsec phase2 selectors for ADVPN shortcut routing.
  • B. BGP per overlay with dynamic BGP for ADVPN shortcut routing.
  • C. BGP per overlay with BGP next-hop convergence for ADVPN shortcut routing.
  • D. BGP on loopback with dynamic BGP for ADVPN shortcut routing.

Answer: D

Explanation:
Using BGP on loopback with dynamic BGP enables scalable routing for large deployments and supports ADVPN shortcut routing with resilient, stable next-hop reachability across dynamic tunnels.


NEW QUESTION # 61
Your FortiGate is in production. To optimize WAN link use and improve redundancy, you enable and configure SD-WAN.
What must you do as part of this configuration update process?

  • A. Replace references to interfaces used as SD-WAN members in the routing configuration.
  • B. Disable the interface that you want to use as an SD-WAN member.
  • C. Replace references to interfaces used as SD-WAN members in the firewall policies.
  • D. Purchase and install the SD-WAN license, and reboot the FortiGate device.

Answer: C

Explanation:
When you enable SD-WAN on a FortiGate, the individual WAN interfaces that you add into the SD-WAN zone are no longer referenced directly in firewall policies.
Instead, you must update those firewall policies to use the SD-WAN zone as the interface reference.


NEW QUESTION # 62
......

FCSS_SDW_AR-7.6 dumps - PrepPDF - 100% Passing Guarantee: https://certkingdom.preppdf.com/Fortinet/FCSS_SDW_AR-7.6-prepaway-exam-dumps.html