FCSS-SDW-AR-7.4 Sample Questions

FCSS-SDW-AR-7.4 Sample Questions & Answers

Basic SD-WAN setup and SLA configuration tie with rules and routing for the heaviest weighting, alongside centralized deployment from FortiManager, IPsec topologies built hub-and-spoke or through ADVPN, and troubleshooting rules, sessions, and routing.

Launch the full FCSS-SDW-AR-7.4 simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    Rules and Routing · Configure SD-WAN rules

    A hospital is implementing a Fortinet SD-WAN solution to connect its main campus with several remote clinics. The primary requirement is to ensure that mission-critical applications, such as Electronic Health Records (EHR) and VoIP, always use the path with the lowest jitter, regardless of latency or packet loss, as long as the path is functional. Which SD-WAN rule configuration best meets this requirement?

    Show answer & explanation

    Correct answer: D

    This is the correct approach. The 'Best Quality' strategy makes its decision based on the metrics defined in the selected Performance SLA. By creating an SLA that exclusively measures jitter, the architect ensures that the path selection for the specified applications will be based solely on which active link has the lowest jitter.

  2. Question 2Beginner

    SD-WAN Configuration · Configure a basic SD-WAN setup

    An administrator is configuring a basic SD-WAN setup with two WAN interfaces, wan1 (MPLS) and wan2 (Broadband). Both are configured as SD-WAN members. The administrator has created a Performance SLA but has not created any SD-WAN rules. How will the FortiGate process traffic destined for the internet?

    Show answer & explanation

    Correct answer: A

    In the absence of any explicit SD-WAN rules, traffic is matched by the default implicit rule. The default behavior of this rule is to load-balance traffic across all available SD-WAN member interfaces using a source IP-based algorithm.

  3. Question 3Advanced

    SD-WAN Troubleshooting · Troubleshoot ADVPN

    An engineer is troubleshooting a multi-hub ADVPN setup where spokes connected to Hub-A are unable to form shortcuts with spokes connected to Hub-B. BGP is running between the hubs, and routes are being exchanged correctly. What is a common misconfiguration that would prevent the inter-hub ADVPN shortcuts from forming?

    Show answer & explanation

    Correct answer: D

    For hubs to facilitate shortcuts for spokes that are not their direct clients, they must be able to forward the IKE information messages used for negotiation. The set auto-discovery-forwarder enable command on the hub's Phase 1 interface allows it to forward these messages to the other hub, which is essential for inter-hub shortcut establishment.

  4. Question 4IntermediateSelect 2

    Centralized Management · Implement the branch configuration deployment

    A systems administrator is tasked with configuring Zero Touch Provisioning (ZTP) for new branch deployments using FortiManager. Which two protocols are primarily used by a new FortiGate to automatically discover and connect to FortiManager during the ZTP process? (Select TWO)

    Show answer & explanation

    Correct answers: B, D

    A new FortiGate, by default, will act as a DHCP client on its WAN interface. It can receive the FortiManager's IP address via DHCP option 240, which is one of the primary methods for ZTP discovery.

    If DHCP discovery fails or is not configured, the FortiGate will attempt to resolve a predefined FQDN (e.g., fortimanager.fortinet.net or a custom one) to find the IP address of its FortiManager, making DNS a key part of the ZTP discovery process.

  5. Question 5Beginner

    SD-WAN Troubleshooting · Troubleshoot SD-WAN rules and sessions behavior

    What is the primary function of the diagnose sys sdwan health-check status command on a FortiGate device?

    Show answer & explanation

    Correct answer: B

    This command provides a detailed, real-time view of each configured Performance SLA health check, showing which member interfaces are being monitored, their current status (alive or dead), and the measured values for latency, jitter, and packet loss.

  6. Question 6Advanced

    Rules and Routing · Configure SD-WAN routing

    An architect is designing an SD-WAN solution with BGP over IPsec. The design requires that if the primary hub fails, spokes must automatically fail over to a secondary hub. The spokes learn about both hubs via BGP. To ensure the secondary hub's routes are only used upon failure of the primary, which BGP attribute should be manipulated on the hubs when advertising routes to the spokes?

    Show answer & explanation

    Correct answer: B

    Local Preference is the ideal attribute for this scenario. The primary hub should advertise routes with a higher Local Preference value (e.g., 200), and the secondary hub should advertise the same routes with a lower Local Preference value (e.g., 150). The spoke's BGP process will prefer the path with the highest Local Preference, directing traffic to the primary hub. If the primary hub fails, its routes are withdrawn, and the spoke then uses the next best path, which is to the secondary hub.

  7. Question 7Intermediate

    SD-WAN Configuration · Configure a basic SD-WAN setup

    A company has configured SD-WAN with two ISP links. They have a critical business application that must be accessible even if one ISP link completely fails. The application is hosted on a public IP, and DNS records point to a single FQDN. How can FortiGate SD-WAN be configured to provide high availability for this inbound service?

    Show answer & explanation

    Correct answer: C

    FortiGate's Virtual Server feature can be configured with an SD-WAN zone as its interface. This allows it to accept inbound traffic from any member interface within that zone. Combined with health checks for the internal server, it can provide high availability for inbound services across multiple ISP links. If one link fails, the service remains accessible via the other.

  8. Question 8Advanced

    Advanced IPsec · Configure IPsec multihub, mulitiregion, and large deployments

    Case Study

    Global Logistics Inc. (GLI) is migrating its legacy WAN to a Fortinet Secure SD-WAN solution managed by FortiManager. They have a central data center (DC), two regional hubs (Hub-US, Hub-EU), and 300 branch offices worldwide. The solution must meet several key business and technical requirements.

    Business Requirements:

    • All branch-to-branch traffic for real-time inventory lookups must be optimized for the lowest latency path and avoid hairpinning through the DC or regional hubs whenever possible.
    • SaaS traffic (Salesforce, Microsoft 365) must be sent directly to the internet from each branch over the link with the best quality.
    • Guest Wi-Fi traffic at branches must be backhauled to the nearest regional hub for security inspection before egressing to the internet.

    Technical Design:

    • All sites are connected via dual IPsec tunnels over public internet links to their nearest regional hub.
    • BGP is used for dynamic routing over the IPsec overlay.
    • FortiManager is used to deploy a standardized configuration template to all 300 branches.

    Given this scenario, which combination of Fortinet SD-WAN features should the architect implement to meet all stated requirements?

    Show answer & explanation

    Correct answer: C

    This is the correct and most complete solution. 1) ADVPN enables direct branch-to-branch shortcuts for inventory traffic, meeting the low-latency requirement. 2) A dedicated SD-WAN rule for SaaS applications with a 'Best Quality' strategy ensures optimal Direct Internet Access (DIA). 3) A separate, higher-priority rule for Guest Wi-Fi traffic that manually steers it over the IPsec tunnels to the hub satisfies the backhauling requirement. The combination of ADVPN and granular, prioritized SD-WAN rules meets all business objectives.

  9. Question 9Intermediate

    SD-WAN Configuration · Configure performances SLAs

    When configuring a Performance SLA, what is the purpose of the 'Link Cost Factor' setting?

    Show answer & explanation

    Correct answer: D

    The 'Link Cost Factor' allows an administrator to assign more weight to a specific quality metric. For example, setting the 'Link Cost Factor' to 'latency' will make the 'Best Quality' strategy prioritize the link with the best latency measurement more heavily than jitter or packet loss when calculating the overall link quality score.

  10. Question 10Intermediate

    Rules and Routing · Configure SD-WAN rules

    A FortiGate is configured with two SD-WAN members, port1 (primary) and port2 (backup). An SD-WAN rule is configured with a spillover load-balancing strategy. The spillover-threshold is set to 10000 kbps for port1. Currently, port1 is passing 8500 kbps of traffic. A user initiates a new 2000 kbps file transfer that matches this rule. How will the FortiGate handle the traffic for this new session?

    Show answer & explanation

    Correct answer: B

    The spillover strategy works on a per-session basis. Before placing a new session, it checks if the current traffic on the primary interface (port1) exceeds the spillover threshold. Since the current 8500 kbps is below the 10000 kbps threshold, it will attempt to place the new session on port1. However, since the new session would push the total above the threshold, the entire new session is 'spilled over' to the next available interface, port2.

Ready for the real thing?

The full FCSS-SDW-AR-7.4 simulator has every exam-style question, timed mode, and instant scoring.