10 free sample questions from a bank of 139, with the correct answers and explanations. No signup required — start practising right now.
1In the context of SD-WAN, the terms underlay and overlay are commonly used to categorize links. Which two statements about underlay and overlay links are correct? (Choose two.)
Overlay links provide routing flexibility.
Only wired connections can be used as underlay links.
A VLAN is a type of overlay link.
FortiLink interface is considered an underlay link.
Wireless connections can be used to build overlay links.
Answer: A, E
The short version
A and E — overlays bring routing flexibility over any transport including wireless. Transport-agnostic agility.
Key concepts in this question
Overlay links build over wired or wireless underlays alike.
Flexibility is the overlay value proposition.
Why A and E are correct
The two documented underlay/overlay truths (matches SSE-Arch Q32).
Why the others are wrong
B. Wireless serves fine as underlay.
C. VLANs segment L2; they are not overlays.
D. FortiLink manages switches/APs; it is not an underlay link.
Secure Networking exam tip
Overlay = any transport + flexibility.
2You have a FortiGate configuration with three user-defined SD-WAN zones and two members in each of these zones. One SD-WAN member is no longer in use in health-check and SD-WAN rules. You want to delete it. What happens if you delete the SD-WAN member from the FortiGate GUI?
FortiGate accepts the SD-WAN member deletion with no further action.
FortiGate displays an error message. SD-WAN zones must contain at least two members.
FortiGate accepts the deletion and removes static routes as required.
FortiGate accepts the deletion and places the member in the default SD-WAN zone.
Answer: A
The short version
A — approved. Deleting an unused SD-WAN member from the GUI simply succeeds with no zone or route side effects.
Key concepts in this question
Unused members: a member referenced by no health-check and no SD-WAN rule is free to remove
GUI deletion: FortiGate validates references and accepts the removal without extra actions
Why A is correct
FortiGate accepts the deletion because the member is no longer in use in health-checks or SD-WAN rules, so there is nothing to clean up or reassign. No minimum-members rule blocks zones with one or zero members.
Why the others are wrong
B. No two-member minimum exists for SD-WAN zones; single-member and empty zones are allowed.
C. No static-route cleanup is triggered; the member was already unused, and static routes are separate objects.
D. Deleted members are not parked in the default virtual-wan-link zone; they are removed.
NSE7_FSN_AR-7.6 exam tip
Unused member delete = just works, no minimum, no move.
3Refer to the exhibits. An OSPF peer is advertising route 172.16.52.0/24. The local FortiGate is configured with an inbound distribution list that allows the 172.16.0.0/14 network to be injected into its routing table. However, the 172.16.52.0/24 subnet cannot be seen in the FIB. Which two steps can the administrator of the local FortiGate take to ensure that the advertised 172.16.52.0/24 subnet will be injected into the routing table? (Choose two.)
Modify the default prefix-list behavior from implicit deny to implicit allow.
Change the ge value to 17.
Add another entry to the prefix list to specifically allow the 172.16.52.0/24 network.
Change the le value to 16.
Answer: B, C
The short version
B and C — exact-match prefix-list blocks the /24; open ge or add an explicit entry. The unset ge/le permits only 172.16.0.0/16 exactly, so the /24 is filtered before the FIB.
Key concepts in this question
Prefix-list exact match: with ge/le unset, only the exact prefix length is permitted.
ge semantics: ge 17 on a /16 base permits lengths 17–32 inside that base.
Explicit entries: a dedicated /24 rule admits the advertised subnet directly.
Why B and C are correct
The exhibit shows prefix 172.16.0.0 255.255.0.0 (/16) with ge and le unset, which matches only /16 exactly, so 172.16.52.0/24 is denied by the inbound distribute-list-in. Setting ge to 17 admits every subnet of length 17–32 within 172.16.0.0/16, including the /24. Adding a separate entry that specifically allows 172.16.52.0/24 likewise injects it without widening anything else.
Why the others are wrong
A. Flipping implicit deny to allow would admit the /24 but also everything else; it is not one of the two targeted fixes.
D. Changing le to 16 keeps the effective match at exactly /16, so the /24 stays filtered.
Secure Networking exam tip
Unset ge/le = exact length only; ge opens longer prefixes.
4Refer to the exhibit. An ADVPN network is shown. You must configure an ADVPN using IBGP for each local region and EBGP across regions to connect Overlay 1 with Overlay 2. Which two options must you configure in the Hub2Hub BGP peering? (Choose two.)
set. ebgp-enforce-multihop enable
set. ibgp-enforce-multihop advpn
set. attribute-unchanged next-hop
set. next-hop-self enable
Answer: A, C
The short version
A and C — Hub2Hub EBGP for ADVPN regions needs multihop plus preserved next-hop. Reach across hops, keep origin truth.
The two documented Hub2Hub settings (2-exam majority over next-hop-self).
Why the others are wrong
B. ibgp-multihop-advpn is a spoke-side knob.
D. next-hop-self rewrites origin, breaking shortcut propagation (Q123's outlier).
Secure Networking exam tip
Hub2Hub EBGP = multihop + unchanged next-hop.
5Refer to the exhibit. You want to configure SD-WAN on a network, as shown in the exhibit. The network contains many FortiGate devices. Some are used as next-generation firewalls (NGFW), and some are installed with extensions such as FortiSwitch, FortiAP, or FortiExtender. Which factors should you consider when planning your deployment?
You should exclude the FortiGate devices with FortiLink connection from the SD-WAN topology.
You should build multiple SD-WAN topologies. Each topology should contain only one type of extension.
You can build an SD-WAN topology that includes all devices. The hubs can be FortiGate devices with FortiExtender.
You can build an SD-WAN topology that includes all devices. The hubs must be devices without extensions.
Answer: D
The short version
D — one SD-WAN topology can include every device, but keep extensions off the hubs. Mixed spokes are supported while hub stability stays paramount.
Key concepts in this question
Single mixed topology: plain FortiGates plus FortiLink, FortiAP, and FortiExtender extensions coexist.
Hub stability: hubs anchor overlays and orchestration, so they stay on plain devices.
Extension spokes: switches, APs, and extenders hang off branches without fracturing the design.
Why D is correct
The exhibit shows a single SD-WAN network topology containing plain FortiGate groups alongside FortiLink-attached pairs and a FortiExtender-attached branch, which directly supports including all devices in one topology rather than excluding types or splitting per extension. Placing hubs on devices without extensions keeps tunnel termination and orchestration stable, while extension-bearing branches join as spokes.
Why the others are wrong
A. Excluding FortiLink devices contradicts the exhibit, which includes them in the topology.
B. Building one topology per extension type is unnecessary; the exhibit shows mixed types together.
C. Making a FortiExtender-bearing device a hub risks WAN instability; hubs must stay extension-free.
Secure Networking exam tip
Mixed SD-WAN = all in, hubs plain.
6Refer to the exhibit. For your ZTP deployment, you review the CSV file shown in exhibit and note that it is missing important information. Which two elements must you change before you can import it into FortiManager? (Choose two.)
You must define a name for each device.
You must define a value for each device and each user-defined metadata variable.
You must associate a device blueprint with each device.
You must define a value for each device and each metadata variable that defines an IP address.
Answer: A, C
The short version
A and C — ZTP CSVs need device names plus blueprint links. Identify, then template.
Key concepts in this question
Device names individualize ZTP entries.
Blueprints bind entries to provisioning logic.
Why A and C are correct
The two documented CSV prerequisites (matches SDW Q53).
Why the others are wrong
B. User-defined metadata is optional.
D. IP metadata is situational.
Secure Networking exam tip
ZTP CSV = names + blueprints.
7Which two troubleshooting steps should you perform if you encounter issues with intermittent web filter behavior? (Choose two.)
Check that the inspection mode configured for the web filter profile matches that of the firewall policy where it is applied.
Check that the correct port is mapped to HTTP in the Protocol Options.
Check that the communication between FortiGate and FortiGuard is stable.
Check that FortiGate is not entering conserve mode.
Answer: C, D
The short version
C and D — flaky web filtering means shaky FortiGuard comms or conserve mode. Intermittent faults, resource causes.
Key concepts in this question
FortiGuard reachability feeds rating lookups.
Conserve mode sheds proxy features under pressure.
Why C and D are correct
The two documented intermittent-fault causes.
Why the others are wrong
A. Mode mismatches break consistently, not intermittently.
B. Port mapping affects protocols, not flakiness.
Secure Networking exam tip
Intermittent filtering = comms or conserve.
8Refer to the exhibit. The output of diagnose sys session list command is shown. If the HA ID for the primary device is 0, what happens if the primary fails and the secondary becomes the primary?
The session state is preserved but the kernel will re-evaluate the session because the routing information will be flushed.
The session is synchronized with the secondary device, however, because application control is applied, the session is marked dirty and has to be re-evaluated after failover.
The session will be removed from the session table of the secondary device because the TCP session is not yet fully established.
The session continues to permit traffic on the new primary device after failover, without requiring the client to restart the session with the server.
Answer: D
The short version
D — HA failover keeps the session alive with no client restart. State sync does its job.
Key concepts in this question
Session synchronization carries established sessions to the new primary.
Routing flushes and app-control dirtiness are edge cases, not the norm framed.
Why D is correct
Seamless continuation is the documented HA outcome.
Why the others are wrong
A. Routing flushes do not gate continued sessions here.
B. App-control dirtiness is not the framed outcome.
C. Established TCP sessions sync normally.
Secure Networking exam tip
HA failover = sessions survive.
9Refer to the exhibit. How does FortiGate handle the traffic with the source IP address 10.0.1.125 and the destination IP address 128.66.0.125?
FortiGate routes the traffic flow according to the forwarding information base (FIB).
FortiGate drops the traffic flow.
FortiGate steers the traffic flow through port7.
FortiGate load balances the traffic flow through port7 and port8.
Answer: D
The short version
D — the flow hits Service(2), which load-balances across port7 and port8. Source and destination both fall inside that service, and both members are alive and selected.
Key concepts in this question
SD-WAN service matching: longest, most specific src/dst service wins over the FIB.
SLA round-robin mode: alive, selected members share matching flows.
FIB precedence: SD-WAN rules steer before the routing table is consulted.
Why D is correct
Source 10.0.1.125 matches Service(2) Src 10.0.1.0–10.0.1.255 and destination 128.66.0.125 matches Dst 128.66.0.0–128.66.255.255, so Service(2) governs. Its two members, Seq 3 on port7 and Seq 4 on port8, are both alive, sla-passing, and selected under Mode sla with hash-mode round-robin, so the flow is load-balanced across port7 and port8 rather than pinned or dropped.
Why the others are wrong
A. FIB routing applies only when no SD-WAN service matches; Service(2) matches here.
B. Nothing is dead or denied; both members show alive, sla pass, and selected.
C. Single-port steering would need priority mode on one member; this service is dual-member round-robin.
Secure Networking exam tip
Match src+dst to the service, then read the mode.
10You use the FortiManager SD-WAN overlay orchestrator to prepare an SD-WAN deployment. Using information provided through the SD-WAN overlay template wizard, FortiManager creates templates that are ready to install on the spoke and hub devices. Which three templates are created by the SD-WAN overlay orchestrator for a spoke device? (Choose three.)
CLI template
Static route template
Rules template
BGP template
IPsec tunnel template
Answer: A, D, E
The short version
A, D, E — spoke orchestrator templates: CLI, BGP, and IPsec tunnel. Same trio as SDW Q57 (letters shift, text matches).
Key concepts in this question
CLI templates carry spoke customization.
BGP plus IPsec templates build routing and tunnels.