Pre-Summer Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dm70dm

NSE6_SDW_AD-7.6 Fortinet NSE 6 - SD-WAN 7.6 Enterprise Administrator Questions and Answers

Questions 4

(Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 4

An SD-WAN zone configuration on the FortiGate GUI is shown.

What can you conclude about the zone and member configuration on this device? Choose one answer.)

Options:

A.

You can delete the virtual-wan-link zone.

B.

The WAN2 zone contains no member.

C.

You can delete the WAN1 zone.

D.

You can add the member B-125 to the WAN3 zone and keep it as a member of the Test zone.

Buy Now
Questions 5

Refer to the exhibit that shows an SD-WAN zone configuration on the FortiManager GUI.

NSE6_SDW_AD-7.6 Question 5

Based on the exhibit, how will the FortiGate device behave after it receives this configuration?

Options:

A.

The configuration instructs FortiGate to choose an ADVPN shortcut based on SD-WAN information.

B.

The configuration instructs FortiGate to allow ADVPN shortcuts for the tunnels of this SD-WAN zone.

C.

The configuration instructs FortiGate to establish shortcuts only when at least two members meet the SLA target.

D.

The configuration instructs FortiGate to establish shortcuts only for overlay interfaces that meet the SLA target HUB1_HC.

Buy Now
Questions 6

Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 6

You configure SD-WAN on a standalone FortiGate device. You want to create an SD-WAN rule that steers Facebook and Linkedin traffic through the less costly internet link. The FortiGate GUI page appears as shown in the exhibit.

What should you do to set Facebook and LinkedIn as destinations?

Options:

A.

Install a license to allow applications as destinations of SD-WAN rules.

B.

In the Internet service field, select Facebook and LinkedIn.

C.

Enable the applications as destinations of the SD-WAN rule feature visibility.

D.

You cannot configure applications as destinations of an SD-WAN rule on a standalone FortiGate device.

Buy Now
Questions 7

(You are using the FortiManager SD-WAN monitor menus to check the status of an SD-WAN topology. When you place the mouse next to branch1_fgt , you receive the output shown in the exhibit.

NSE6_SDW_AD-7.6 Question 7

Which two conclusions can you draw from the output shown in the exhibit? Choose two answers.)

Options:

A.

Three spokes have tunnels that are out of SLA.

B.

The template Corp-SOT defines a dual-hub topology.

C.

branch3_fgt is configured with three SD-WAN overlay tunnels and one is down.

D.

branch1_fgt is configured with six SD-WAN overlay tunnels and three are down.

Buy Now
Questions 8

(Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 8

Which statement correctly describes the role of the ADVPN device in handling traffic? Choose one answer.)

Options:

A.

This device is a spoke that has received a direct shortcut query from a remote spoke.

B.

This device is a hub, and two spokes, 192.2.0.1 and 10.0.3.101, established a shortcut.

C.

This device is a hub that has received a shortcut query from a spoke and has forwarded it to another spoke.

D.

This device is a spoke that has received a shortcut query from a remote hub.

Buy Now
Questions 9

(Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 9

Based on the output shown in the exhibit, what can you conclude about the device role and how it handles health checks? Choose one answer.)

Options:

A.

The device is a spoke and it provides embedded health-check measures for each tunnel to the hub.

B.

The device is a spoke and it receives health-check measures for the tunnels of another spoke.

C.

The device is a hub and it receives embedded health-check measures for each tunnel from the spoke.

D.

The device is a hub and it receives health-check measures for the tunnels of a spoke.

Buy Now
Questions 10

(Refer to the exhibits.

NSE6_SDW_AD-7.6 Question 10

You collected the output shown in the exhibits and want to know which interface HTTP traffic will flow through from the user device 10.0.1.101 to the corporate web server 10.0.0.126 . All SD-WAN links are stable.

Which interface will FortiGate use to steer the traffic? Choose one answer.)

Options:

A.

Only HUB1-VPN3

B.

Only HUB1-VPN2

C.

Either HUB1-VPN2 or HUB1-VPN3

D.

Either HUB1-VPN1 , HUB1-VPN2 , or HUB1-VPN3

Buy Now
Questions 11

Exhibit.

NSE6_SDW_AD-7.6 Question 11

Refer to the exhibit, which shows the SD-WAN rule status and configuration.

Based on the exhibit, which change in the measured packet loss will make HUB1-VPN3 the new preferred member?

Options:

A.

When HUB1-VPN1 has 4% packet loss

B.

When HUB1-VPN1 has 12% packet loss

C.

When HUB1-VPN3 has 4% packet loss

D.

When all three members have the same packet loss

Buy Now
Questions 12

You want FortiGate to use SD-WAN rules to steer local-out traffic.

Which two constraints should you consider? (Choose two.)

Options:

A.

By default, FortiGate uses SD-WAN rules only for local-out traffic that corresponds to ping and traceroute.

B.

By default, local-out traffic does not use SD-WAN.

C.

You can steer local-out traffic only with SD-WAN rules that use the manual strategy.

D.

You must configure each local-out feature individually to use SD-WAN.

Buy Now
Questions 13

Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 13

The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths. However, when looking at the spoke routing table, the administrator does not see the prefixes from other spokes and the additional paths

Which three settings must the administrator configure inside each BGP neighbor group so spokes can learn the prefixes of other spokes and their additional paths? (Choose three.)

Options:

A.

Set additional-path to send

B.

Set additional-path to forward

C.

Enable route-reflector-server

D.

Enable route-reflector-client.

E.

Set adv-additional-path to the number of additional paths to advertise.

Buy Now
Questions 14

Refer to the exhibits.

NSE6_SDW_AD-7.6 Question 14

NSE6_SDW_AD-7.6 Question 14

The exhibits show the SD-WAN zone configuration of an SD-WAN template prepared on FortiManager and the policy package configuration.

When the administrator tries to install the configuration changes, FortiManager fails to commit.

What should the administrator do to fix the issue?

Options:

A.

Configure branch1_fgt as the installation target for policy 3.

B.

Configure HUB1 as the destination of policy 3.

C.

Configure a normalized interface for the IPsec tunnel HUB1-VPN1.

D.

Configure both HUB1-VPN1 and HUB1-VPN2 as the destination of policy 3

Buy Now
Questions 15

(As an IT manager, you want to delegate the installation and management of your SD-WAN deployment to a managed security service provider (MSSP). Each site must maintain direct internet access and be secure. You expect significant traffic flow between the sites and want to delegate as much of the network administration and management as possible to the MSSP.

Which two MSSP deployment blueprints address your requirements? Choose two answers.)

Options:

A.

Use a shared hub on the MSSP premises and a dedicated hub on the customer premises, and install the spokes on the customer premises.

B.

Install a dedicated hub on the MSSP premises for the customer, and install the spokes on the customer premises.

C.

Install the hub and spokes on the customer premises, and enable the MSSP to manage the SD-WAN deployment using FortiManager with a dedicated ADOM.

D.

Use a shared hub on the MSSP premises with a dedicated VDOM for the customer, and install the spokes on the customer premises.

Buy Now
Questions 16

Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 16

Which SD-WAN rule and interface uses FortiGate to steer the traffic from the LAN subnet 10.0.1.0/24 to the corporate server 10.2.5.254?

Options:

A.

SD-WAN service rule 3 and interface HUB1-VPN2.

B.

SD-WAN service rule 3 and interface HUB1-VPN3.

C.

SD-WAN service rule 4 and port1 or port2.

D.

SD-WAN service rule 4 and interface port2.

Buy Now
Questions 17

Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 17

The administrator configured the SD-WAN rule ID 4 with two members (port1 and port2) and strategy lowest cost (SLA).

What are the two characteristics of the session shown in the exhibit? (Choose two.)

Options:

A.

FortiGate steered this flow according to an SD-WAN rule 4.

B.

FortiGate will never re-evaluate this session.

C.

FortiGate steered this flow according to the application detected and the outgoing interface is port3.

D.

FortiGate will re-evaluate this session if the outgoing interface goes down.

Buy Now
Questions 18

Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 18

An administrator checks the status of an SD-WAN topology using the FortiManager SD-WAN monitor menus. All members are configured with one or two SLAs.

Which two conclusions can you draw from the output shown? (Choose two.)

Options:

A.

The template view should be used to see the hub devices.

B.

One member of branch2_fgt is missing the SLAs.

C.

branch2_fgt establishes six tunnels to the hubs and they are all up.

D.

This SD-WAN topology contains only two branch devices.

Buy Now
Questions 19

To secure your enterprise network traffic, which step does FortiGate perform first, when handling the first packets of a session? (Choose one answer)

Options:

A.

Installation of the session key in the network processor (NP)

B.

Decryption

C.

A reverse path forwarding (RPF) check

D.

IP integrity header checking

Buy Now
Questions 20

Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 20

An administrator configures SD-WAN rules for a DIA setup using the FortiGate GUI. The page to configure the source and destination part of the rule looks as shown in the exhibit. The GUI page shows no option to configure an application as the destination of the SD-WAN rule Why?

Options:

A.

You cannot use applications as the destination when FortiGate is used for a DIA setup.

B.

FortiGate allows the configuration of applications as the destination of SD-WAN rules only on the CLI.

C.

You must enable the feature on the CLI.

D.

You must enable the feature first using the GUI menu System > Feature Visibility.

Buy Now
Questions 21

Refer to the exhibits.

NSE6_SDW_AD-7.6 Question 21

NSE6_SDW_AD-7.6 Question 21

The administrator configured a device blueprint and CLI scripts as shown in the exhibits, to prepare for onboarding FortiGate devices in the company’s stores. Later, a technician prepares a FortiGate 51G with a basic configuration and connects it to the network. The basic configuration contains the port1 configuration and the minimal configuration required to allow the device to connect to FortiManager.

After the device first connects to FortiManager, FortiManager updates the device configuration.

Based on the exhibits, which actions does FortiManager perform?

Options:

A.

FortiManager updates the device configuration according to the selected templates. It applies the corp_st template first.

B.

FortiManager does not update the port1 configuration because FortiManager does not change the configuration of interfaces with fgfm access.

C.

FortiManager updates access rights only for port1. FortiManager cannot update the IP address because it was already set manually.

D.

FortiManager updates the configuration of port1, port2, and port5. The three ports might get new IP addresses.

Buy Now
Questions 22

Your FortiGate is in production. To optimize WAN link use and improve redundancy, you enable and configure SD-WAN.

What must you do as part of this configuration update process?

Options:

A.

Replace references to interfaces used as SD-WAN members in the routing configuration.

B.

Purchase and install the SD-WAN license, and reboot the FortiGate device.

C.

Replace references to interfaces used as SD-WAN members in the firewall policies.

D.

Disable the interface that you want to use as an SD-WAN member.

Buy Now
Questions 23

Exhibit.

NSE6_SDW_AD-7.6 Question 23

For your ZTP deployment, you review the CSV file shown in exhibit and note that it is missing important information. Which two elements must you change before you can import it into FortiManager? (Choose two.)

Options:

A.

You must associate a device blueprint with each device

B.

You must define a name for each device

C.

You must define a value for each device and each metadata variable that defines an IP address.

D.

You must define a value for each device and each user-defined metadata variable.

Buy Now
Questions 24

Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 24

The administrator analyzed the traffic between a branch FortiGate and the server located in the data center, and noticed the behavior shown in the diagram.

When the LAN clients located behind FGT1 establish a session to a server behind DC-1, the administrator observes that, on DC-1, the reply traffic is routed overT2. even though T1 is the preferred member in

the matching SD-WAN rule.

What can the administrator do to instruct DC-1 to route the reply traffic through the member with the best performance?

Options:

A.

Enable snat-route-change under config system global.

B.

Enable reply-session under config system sdwan.

C.

Enable auxiliary-session under config system settings.

D.

FortiGate route lookup for reply traffic only considers routes over the original ingress interface.

Buy Now
Questions 25

(Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 25

You configure SD-WAN on a standalone FortiGate device.

You want to create an SD-WAN rule that steers traffic related to Facebook and LinkedIn through the less costly internet link.

What must you do to set Facebook and LinkedIn applications as destinations from the GUI? Choose one answer.)

Options:

A.

Enable the visibility of the applications field as destinations of the SD-WAN rule.

B.

In the Internet service field, select Facebook and LinkedIn.

C.

You cannot configure applications as destinations of an SD-WAN rule on a standalone FortiGate device.

D.

Install a license to allow applications as destinations of SD-WAN rules.

Buy Now
Questions 26

(Refer to the exhibit.

NSE6_SDW_AD-7.6 Question 26

You update the spokes configuration of an existing auto-discovery VPN (ADVPN) topology by adding the parameters shown in the exhibit.

Which is a valid objective of those settings? Choose one answer.)

Options:

A.

Enable the tunnels as overlay links.

B.

Convert the configuration from ADVPN to ADVPN 2.0.

C.

Prevent cross-overlay shortcuts.

D.

Prevent multiple shortcuts from being established over the same overlay.

Buy Now
Questions 27

Which two statements correctly describe what happens when traffic matches the implicit SD-WAN rule? (Choose two.)

Options:

A.

The session information output displays no SD-WAN service id.

B.

Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.

C.

The traffic is distributed, regardless of weight, through all available static routes.

D.

Traffic does not match any of the entries in the policy route table.

E.

FortiGate flags the session with may_dirty and vwl_def ault.

Buy Now
Questions 28

Refer to the exhibits.

NSE6_SDW_AD-7.6 Question 28

An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in the first exhibit. After generating GoToMeeting test traffic, the administrator examined the corresponding traffic log on FortiAnalyzer, which is shown in the second exhibit.

The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.

Which two reasons explain why some log messages show that the traffic matched the implicit SD-WAN rule? (Choose two.)

Options:

A.

Full SSL inspection is not enabled on the matching firewall policy.

B.

The session 3-tuple did not match any of the existing entries in the ISDB application cache.

C.

FortiGate could not refresh the routing information on the session after the application was detected.

D.

No configured SD-WAN rule matches the traffic related to the collaboration application GoToMeeting

Buy Now
Exam Code: NSE6_SDW_AD-7.6
Exam Name: Fortinet NSE 6 - SD-WAN 7.6 Enterprise Administrator
Last Update: Apr 18, 2026
Questions: 96

PDF + Testing Engine

$49.5  $164.99

Testing Engine

$37.5  $124.99
buy now NSE6_SDW_AD-7.6 testing engine

PDF (Q&A)

$31.5  $104.99
buy now NSE6_SDW_AD-7.6 pdf
dumpsmate guaranteed to pass

24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 18 Apr 2026