FCSS-SDW-AR-7.4 Sample Questions & Answers
Basic SD-WAN setup and SLA configuration tie with rules and routing for the heaviest weighting, alongside centralized deployment from FortiManager, IPsec topologies built hub-and-spoke or through ADVPN, and troubleshooting rules, sessions, and routing.
Launch the full FCSS-SDW-AR-7.4 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Rules and Routing · Configure SD-WAN rules
A hospital is implementing a Fortinet SD-WAN solution to connect its main campus with several remote clinics. The primary requirement is to ensure that mission-critical applications, such as Electronic Health Records (EHR) and VoIP, always use the path with the lowest jitter, regardless of latency or packet loss, as long as the path is functional. Which SD-WAN rule configuration best meets this requirement?
Show answer & explanation
Correct answer: D
This is the correct approach. The 'Best Quality' strategy makes its decision based on the metrics defined in the selected Performance SLA. By creating an SLA that exclusively measures jitter, the architect ensures that the path selection for the specified applications will be based solely on which active link has the lowest jitter.
- Question 2Beginner
SD-WAN Configuration · Configure a basic SD-WAN setup
An administrator is configuring a basic SD-WAN setup with two WAN interfaces, wan1 (MPLS) and wan2 (Broadband). Both are configured as SD-WAN members. The administrator has created a Performance SLA but has not created any SD-WAN rules. How will the FortiGate process traffic destined for the internet?
Show answer & explanation
Correct answer: A
In the absence of any explicit SD-WAN rules, traffic is matched by the default implicit rule. The default behavior of this rule is to load-balance traffic across all available SD-WAN member interfaces using a source IP-based algorithm.
- Question 3Advanced
SD-WAN Troubleshooting · Troubleshoot ADVPN
An engineer is troubleshooting a multi-hub ADVPN setup where spokes connected to Hub-A are unable to form shortcuts with spokes connected to Hub-B. BGP is running between the hubs, and routes are being exchanged correctly. What is a common misconfiguration that would prevent the inter-hub ADVPN shortcuts from forming?
Show answer & explanation
Correct answer: D
For hubs to facilitate shortcuts for spokes that are not their direct clients, they must be able to forward the IKE information messages used for negotiation. The
set auto-discovery-forwarder enablecommand on the hub's Phase 1 interface allows it to forward these messages to the other hub, which is essential for inter-hub shortcut establishment. - Question 4IntermediateSelect 2
Centralized Management · Implement the branch configuration deployment
A systems administrator is tasked with configuring Zero Touch Provisioning (ZTP) for new branch deployments using FortiManager. Which two protocols are primarily used by a new FortiGate to automatically discover and connect to FortiManager during the ZTP process? (Select TWO)
Show answer & explanation
Correct answers: B, D
A new FortiGate, by default, will act as a DHCP client on its WAN interface. It can receive the FortiManager's IP address via DHCP option 240, which is one of the primary methods for ZTP discovery.
If DHCP discovery fails or is not configured, the FortiGate will attempt to resolve a predefined FQDN (e.g.,
fortimanager.fortinet.netor a custom one) to find the IP address of its FortiManager, making DNS a key part of the ZTP discovery process. - Question 5Beginner
SD-WAN Troubleshooting · Troubleshoot SD-WAN rules and sessions behavior
What is the primary function of the
diagnose sys sdwan health-check statuscommand on a FortiGate device?Show answer & explanation
Correct answer: B
This command provides a detailed, real-time view of each configured Performance SLA health check, showing which member interfaces are being monitored, their current status (alive or dead), and the measured values for latency, jitter, and packet loss.
- Question 6Advanced
Rules and Routing · Configure SD-WAN routing
An architect is designing an SD-WAN solution with BGP over IPsec. The design requires that if the primary hub fails, spokes must automatically fail over to a secondary hub. The spokes learn about both hubs via BGP. To ensure the secondary hub's routes are only used upon failure of the primary, which BGP attribute should be manipulated on the hubs when advertising routes to the spokes?
Show answer & explanation
Correct answer: B
Local Preference is the ideal attribute for this scenario. The primary hub should advertise routes with a higher Local Preference value (e.g., 200), and the secondary hub should advertise the same routes with a lower Local Preference value (e.g., 150). The spoke's BGP process will prefer the path with the highest Local Preference, directing traffic to the primary hub. If the primary hub fails, its routes are withdrawn, and the spoke then uses the next best path, which is to the secondary hub.
- Question 7Intermediate
SD-WAN Configuration · Configure a basic SD-WAN setup
A company has configured SD-WAN with two ISP links. They have a critical business application that must be accessible even if one ISP link completely fails. The application is hosted on a public IP, and DNS records point to a single FQDN. How can FortiGate SD-WAN be configured to provide high availability for this inbound service?
Show answer & explanation
Correct answer: C
FortiGate's Virtual Server feature can be configured with an SD-WAN zone as its interface. This allows it to accept inbound traffic from any member interface within that zone. Combined with health checks for the internal server, it can provide high availability for inbound services across multiple ISP links. If one link fails, the service remains accessible via the other.
- Question 8Advanced
Advanced IPsec · Configure IPsec multihub, mulitiregion, and large deployments
Case Study
Global Logistics Inc. (GLI) is migrating its legacy WAN to a Fortinet Secure SD-WAN solution managed by FortiManager. They have a central data center (DC), two regional hubs (Hub-US, Hub-EU), and 300 branch offices worldwide. The solution must meet several key business and technical requirements.
Business Requirements:
- All branch-to-branch traffic for real-time inventory lookups must be optimized for the lowest latency path and avoid hairpinning through the DC or regional hubs whenever possible.
- SaaS traffic (Salesforce, Microsoft 365) must be sent directly to the internet from each branch over the link with the best quality.
- Guest Wi-Fi traffic at branches must be backhauled to the nearest regional hub for security inspection before egressing to the internet.
Technical Design:
- All sites are connected via dual IPsec tunnels over public internet links to their nearest regional hub.
- BGP is used for dynamic routing over the IPsec overlay.
- FortiManager is used to deploy a standardized configuration template to all 300 branches.
Given this scenario, which combination of Fortinet SD-WAN features should the architect implement to meet all stated requirements?
Show answer & explanation
Correct answer: C
This is the correct and most complete solution. 1) ADVPN enables direct branch-to-branch shortcuts for inventory traffic, meeting the low-latency requirement. 2) A dedicated SD-WAN rule for SaaS applications with a 'Best Quality' strategy ensures optimal Direct Internet Access (DIA). 3) A separate, higher-priority rule for Guest Wi-Fi traffic that manually steers it over the IPsec tunnels to the hub satisfies the backhauling requirement. The combination of ADVPN and granular, prioritized SD-WAN rules meets all business objectives.
- Question 9Intermediate
SD-WAN Configuration · Configure performances SLAs
When configuring a Performance SLA, what is the purpose of the 'Link Cost Factor' setting?
Show answer & explanation
Correct answer: D
The 'Link Cost Factor' allows an administrator to assign more weight to a specific quality metric. For example, setting the 'Link Cost Factor' to 'latency' will make the 'Best Quality' strategy prioritize the link with the best latency measurement more heavily than jitter or packet loss when calculating the overall link quality score.
- Question 10Intermediate
Rules and Routing · Configure SD-WAN rules
A FortiGate is configured with two SD-WAN members,
port1(primary) andport2(backup). An SD-WAN rule is configured with aspilloverload-balancing strategy. Thespillover-thresholdis set to 10000 kbps forport1. Currently,port1is passing 8500 kbps of traffic. A user initiates a new 2000 kbps file transfer that matches this rule. How will the FortiGate handle the traffic for this new session?Show answer & explanation
Correct answer: B
The spillover strategy works on a per-session basis. Before placing a new session, it checks if the current traffic on the primary interface (
port1) exceeds the spillover threshold. Since the current 8500 kbps is below the 10000 kbps threshold, it will attempt to place the new session onport1. However, since the new session would push the total above the threshold, the entire new session is 'spilled over' to the next available interface,port2.
Ready for the real thing?
The full FCSS-SDW-AR-7.4 simulator has every exam-style question, timed mode, and instant scoring.