[2026年01月29日] 最新FCSS_SDW_AR-7.4試験問題集には高得点で一発合格 [Q35-Q56]

Share

[2026年01月29日] 最新FCSS_SDW_AR-7.4試験問題集には高得点で一発合格

無料提供中FCSS_SDW_AR-7.4ブレーン問題集とFCSS_SDW_AR-7.4リアル試験問題

質問 # 35
Refer to the exhibit. How does FortiGate handle the traffic with the source IP 10.0.1.130 and the destination IP 128.66.0 125?

  • A. FortiGate drops the traffic flow.
  • B. FortiGate steers the traffic flow through port2.
  • C. FortiGate routes the traffic flow according to the FIB.
  • D. FortiGate load balances the traffic flow through port1 and port2.

正解:A

解説:
The router policy explicitly denies traffic with source 10.0.1.128/25 (which includes 10.0.1.130) and destination 128.66.0.0/24 (which includes 128.66.0.125). Even though SD-WAN service 4 shows members (port1 and port2) alive and available for this traffic, the router policy is evaluated first and blocks it. Therefore, FortiGate drops the traffic flow.


質問 # 36
Refer to the exhibit.

An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network.
The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over HUB1-VPN1. However, the traffic is routed over HUB1-VPN3.
Based on the output shown in the exhibit, which two reasons, individually or together, could explain the observed behavior? (Choose two.)

  • A. HUB1-VPN3 has a lower route priority value (higher priority) than HUB1-VPN1.
  • B. The traffic matches a regular policy route configured with HUB1-VPN3 as the outgoing device
  • C. HUB1-VPN1 does not have a valid route to the destination
  • D. HUB1-VPN3 has a higher member configuration priority than HUB1-VPN1.

正解:A、D


質問 # 37
Refer to the exhibit. Which statement best describe the role of the ADVPN device in handling traffic?

  • A. This is a spoke. The kernel received a shortcut request and forwards the query to another spoke.
  • B. This is a spoke that has received a shortcut query from another spoke and has forwarded the response to its hub.
  • C. This is a hub in a dual-region topology. The remote hub tunnel ID is 10.0.2.101.
  • D. This is a hub that has received a query from a spoke and has forwarded it to another spoke.

正解:D

解説:


質問 # 38
Exhibit.

For your ZTP deployment, you review the CSV file shown in exhibit and note that it is missing important information. Which two elements must you change before you can import it into FortiManager? (Choose two.)

  • A. You must associate a device blueprint with each device
  • B. You must define a name for each device
  • C. You must define a value for each device and each user-defined metadata variable.
  • D. You must define a value for each device and each metadata variable that defines an IP address.

正解:A、B


質問 # 39
Refer to the exhibit.

Which two conclusions can you draw from the output shown? (Choose two.)

  • A. UDP traffic destined to the subnet 10.22.0.0/24 matches a manual SD-WAN rule.
  • B. One SD-WAN rule allows traffic load balancing.
  • C. UDP traffic destined to the subnet 10.22.0.0/24 matches a policy route.
  • D. One SD-WAN rule is defined with application categories as the destination.

正解:C、D

解説:
One SD-WAN rule is defined with application categories as the destination # The diagnose output shows application control matches such as Microsoft.Portal, Operational.Technology, and Social.Media, confirming that SD-WAN rules are using application categories as destinations.
UDP traffic destined to the subnet 10.22.0.0/24 matches a policy route # The first entry (id=1) shows protocol=17 (UDP) with destination 10.22.0.0/24, confirming this traffic is handled by a policy route instead of an SD-WAN rule.


質問 # 40
An SD-WAN member is no longer used to steer SD-WAN traffic. The administrator updated the SD-WAN configuration and deleted the unused member. After the configuration update, users report that some destinations are unreachable. You confirm that the affected flow does not match an SD-WAN rule.
What could be a possible cause of the traffic interruption?

  • A. FortiGate, with SD-WAN enabled, cannot route traffic through interfaces that are not SD-WAN members.
  • B. FortiGate can remove some static routes associated with an interface when the member is removed from SD-WAN.
  • C. FortiGate removes the layer 3 settings for interfaces that are removed from the SD-WAN configuration.
  • D. FortiGate administratively brings down interfaces when they are removed from the SD-WAN configuration.

正解:B

解説:
When an SD-WAN member is deleted, FortiGate can also remove static routes that were tied to that interface.
If those routes are needed for destinations not covered by SD-WAN rules, traffic to those networks becomes unreachable. This explains why flows not matching SD-WAN rules are interrupted after the member was removed.


質問 # 41
Refer to the exhibits.

You use FortiManager to manage the branch devices and configure the SD-WAN template. You have configured direct internet access (DIA) for the IT department users. Now. you must configure secure internet access (SIA) for all local LAN users and have set the firewall policies as shown in the second exhibit.
Then, when you use the install wizard to install the configuration and the policy package on the branch devices, FortiManager reports an error as shown in the third exhibit.
Which statement describes why FortiManager could not install the configuration on the branches?

  • A. You must direct SIA traffic to a VPN tunnel.
  • B. You cannot install firewall policies that reference an SD-WAN member.
  • C. You cannot install firewall policies that reference an SD-WAN zone.
  • D. You cannot install SIA and DIA rules on the same device.

正解:B

解説:
FortiManager enforces a strict distinction:
"Firewall policies must reference SD-WAN zones, not individual SD-WAN members, when used in conjunction with SD-WAN templates. Attempting to install a policy that references a specific member (interface) will result in a deployment error, as member-level targeting is not supported in SD-WAN policy abstraction. This enforces centralized policy consistency and proper SD-WAN operation." Ensuring policies target zones allows FortiGate to dynamically select the optimal member.


質問 # 42
Refer to the exhibit.

Which statement best describe the role of the ADVPN device in handling traffic?

  • A. This is a hub that has received a query from a spoke and has forwarded it to another spoke.
  • B. This is a spoke. The kernel received a shortcut request and forwards the query to another spoke.
  • C. This is a spoke that has received a shortcut query from another spoke and has forwarded the response to its hub.
  • D. This is a hub in a dual-region topology. The remote hub tunnel ID is 10.0.2.101.

正解:C


質問 # 43
Refer to the exhibit.

The administrator analyzed the traffic between a branch FortiGate and the server located in the data center, and noticed the behavior shown in the diagram.
When the LAN clients located behind FGT1 establish a session to a server behind DC-1, the administrator observes that, on DC-1, the reply traffic is routed overT2. even though T1 is the preferred member in the matching SD-WAN rule.
What can the administrator do to instruct DC-1 to route the reply traffic through the member with the best performance?

  • A. FortiGate route lookup for reply traffic only considers routes over the original ingress interface.
  • B. Enable reply-session under config system sdwan.
  • C. Enable snat-route-change under config system global.
  • D. Enable auxiliary-session under config system settings.

正解:B

解説:
When asymmetric routing is observed (such as reply traffic not following the optimal path), the solution is:
"The auxiliary-session feature, enabled under config system settings, allows FortiGate to consider multiple egress interfaces for reply traffic, not just the original ingress interface. This is crucial for SD-WAN environments where the best path may differ between forward and return directions, especially when performance or policy rules are dynamically evaluated." Activating this ensures reply traffic is always sent on the member with the best real-time metrics.
References:
[FCSS_SDW_AR-7.4 1-0.docx Q23]
FortiOS 7.4 CLI Reference, "auxiliary-session for SD-WAN Path Optimization"


質問 # 44
Refer to the exhibit. Which SD-WAN rule and interface uses FortiGate to steer the traffic from the LAN subnet 10.0.1.0/24 to the corporate server 10.2.5.254?

  • A. SD-WAN service rule 4 and port1 or port2.
  • B. SD-WAN service rule 3 and interface HUB1-VPN3.
  • C. SD-WAN service rule 4 and interface port2.
  • D. SD-WAN service rule 3 and interface HUB1-VPN2.

正解:B


質問 # 45
An SD-WAN member is no longer used to steer SD-WAN traffic. The administrator updated the SD-WAN configuration and deleted the unused member. After the configuration update, users report that some destinations are unreachable. You confirm that the affected flow does not match an SD-WAN rule.
What could be a possible cause of the traffic interruption?

  • A. FortiGate, with SD-WAN enabled, cannot route traffic through interfaces that are not SD-WAN members.
  • B. FortiGate can remove some static routes associated with an interface when the member is removed from SD-WAN.
  • C. FortiGate removes the layer 3 settings for interfaces that are removed from the SD-WAN configuration.
  • D. FortiGate administratively brings down interfaces when they are removed from the SD-WAN configuration.

正解:B

解説:
When an SD-WAN member is deleted, FortiGate can also remove static routes that were tied to that interface.
If those routes are needed for destinations not covered by SD-WAN rules, traffic to those networks becomes unreachable. This explains why flows not matching SD-WAN rules are interrupted after the member was removed.


質問 # 46
You have configured the performance SLA with the probe mode as Prefer Passive.
What are two observable impacts of this configuration? (Choose two.)

  • A. FortiGate can offload the traffic that is subject to passive monitoring to hardware.
  • B. After FortiGate switches to active mode, the SLA performance rule falls back to passive monitoring after 3 minutes.
  • C. FortiGate passively monitors the member if TCP traffic is passing through the member.
  • D. FortiGate passively monitors the member if ICMP traffic is passing through the member.
  • E. During passive monitoring, the SLA performance rule cannot detect dead members.

正解:C、D

解説:
FortiGate passively monitors the member if TCP traffic is passing through the member → With Prefer Passive mode, FortiGate inspects existing traffic (like TCP flows) to measure performance metrics without generating its own probes.
FortiGate passively monitors the member if ICMP traffic is passing through the member → Similarly, when ICMP flows exist, FortiGate uses them for SLA checks.


質問 # 47
Refer to the exhibit, which shows the SD-WAN rule status and configuration.

Based on the exhibit, which change in the measured latency will first make HUB1-VPN3 the new preferred member?

  • A. When HUB1-VPN1 has a latency of 200 ms
  • B. When HUB1-VPN3 has a lower latency than HUB1-VPN1 and HUB1-VPN2
  • C. When HUB1-VPN3 has a latency of 90 ms
  • D. When HUB1-VPN3 has a latency of 80 ms

正解:A

解説:
The rule is in priority mode with HUB1-VPN1 (seq 4) as the first preferred member, HUB1-VPN2 second, and HUB1-VPN3 third. Latency itself does not cause HUB1-VPN3 to become preferred unless a higher-priority member fails SLA. If HUB1-VPN1's latency exceeds the SLA threshold (here simulated by latency reaching 200 ms), FortiGate stops using it and moves down the priority list. That is when HUB1-VPN3 could become the active path.


質問 # 48
An administrator is configuring SD-WAN to load balance their network traffic. Which two things should they consider when setting up SD-WAN? (Choose two.)

  • A. When applicable. FortiGate load balances the traffic through all members that meet the SLA target.
  • B. You can select the outbandwidth hash mode with all strategies that allow load balancing.
  • C. Only the manual and best-quality strategies allow SD-WAN load balancing.
  • D. SD-WAN load balancing is possible only using the best quality and lowest cost (SLA) strategies.

正解:B、D


質問 # 49
Refer to the exhibit, which shows an SD-WAN zone configuration on the FortiGate GUI. What can you conclude about the zone and member configuration on this device?

  • A. The overlay-factories zone contains no member.
  • B. The underlay zone contains three members.
  • C. You can move HUB1-VPN3 from the HUB1 zone to the overlay-shops zone.
  • D. You can delete the virtual-wan-link zones.

正解:A


質問 # 50
Refer to the exhibit.

The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths.
However, when looking at the spoke routing table, the administrator does not see the prefixes from other spokes and the additional paths Which three settings must the administrator configure inside each BGP neighbor group so spokes can learn the prefixes of other spokes and their additional paths? (Choose three.)

  • A. Enable route-reflector-server
  • B. Set adv-additional-path to the number of additional paths to advertise.
  • C. Set additional-path to send
  • D. Set additional-path to forward
  • E. Enable route-reflector-client.

正解:B、C、E

解説:
The hub must send additional paths to spokes (set additional-path send).
The hub must treat each spoke as a route-reflector client so spoke routes are reflected to other spokes.
The hub must specify how many additional paths to advertise (set adv-additional-path <n>).


質問 # 51
Refer to the exhibits. The first exhibit shows the SD-WAN zone HUB1 and SD-WAN member configuration from an SD-WAN template, and the second exhibit shows the output of command diagnose sys sdwan membercollected on a FortiGate device.
Which statement best describes what the diagnose output shows?


  • A. The diagnose output was collected on the device branch1_fgt
  • B. The diagnose output does not correspond to a device configured with the SD-WAN template shown in the exhibit.
  • C. The diagnose output shows that HUB1-VPN1 and all HUBx-VPNy members are dead.
  • D. The diagnose output was collected on the device branch2_fgt.

正解:A

解説:
The diagnose output lists SD-WAN members 4(HUB1-VPN1), 5(HUB1-VPN2), 7(HUB2-VPN1),
8(HUB2-VPN2), and 9(HUB2-VPN3). It does not include member 6 (HUB1-VPN3). From the template, HUB1-VPN3 is installed only on branch2_fgt and branch3_fgt - not on branch1_fgt.
Therefore, the output must be from branch1_fgt.


質問 # 52
You want FortiGate to use SD-WAN rules to steer local-out traffic.
Which two constraints should you consider? (Choose two.)

  • A. You must configure each local-out feature individually to use SD-WAN.
  • B. You can steer local-out traffic only with SD-WAN rules that use the manual strategy.
  • C. By default, local-out traffic does not use SD-WAN.
  • D. By default, FortiGate uses SD-WAN rules only for local-out traffic that corresponds to pingand traceroute.

正解:A、C

解説:
By default, local-out traffic does not use SD-WAN → FortiGate normally sends local-out traffic (e.g., DNS, NTP, FortiGuard updates) directly through its interfaces without applying SD-WAN rules.
You must configure each local-out feature individually to use SD-WAN → To steer local-out traffic via SD-WAN, you must explicitly configure the desired local-out features (e.g., DNS, FortiGuard, CAPWAP) to use SD-WAN rules.


質問 # 53
Refer to the exhibits. The exhibits show two IPsec templates to define Branch IPsec 1 and Branch_IPsec_2. Each template defines a VPN tunnel. The error message that FortiManager displayed when the administrator tried to assign the second template to the FortiGate device is also shown. Which statement best describes the cause of the issue?

  • A. You can assign only one template with a tunnel type of static to each FortiGate device.
  • B. You can assign only one IPsec template to each FortiGate device.
  • C. You should use the same outgoing interface of both templates.
  • D. You should review the branch1_fgt configuration for configured tunnels in the rootVDOM.

正解:B

解説:
FortiManager allows only one IPsec template to be assigned per FortiGate device. The error indicates a conflicting template assignment, meaning assigning both Branch_IPsec_1 and Branch_IPsec_2 to the same device (branch1_fgt) is not permitted.


質問 # 54
Refer to the exhibit.

The exhibit shows the health-check configuration on a FortiGate device used as a spoke. You notice that the hub FortiGate doesn't prioritize the traffic as expected.
Which two configuration elements should you check on the hub? (Choose two.)

  • A. The performance SLA has the parameter priority-out-sla configured.
  • B. The performance SLA is configured with set embedded-measure accept.
  • C. The performance SLA uses the same criteria.
  • D. This performance SLA uses the same members.

正解:B、C

解説:
The hub must use a performance SLA with the same criteria as the spoke's health check. The spoke's health check is using ping (protocol ping) and measuring latency (link-cost-factor latency). For the hub to use the data sent by the spoke, its performance SLA must be configured to measure the same metrics. If the hub is looking for jitter or packet loss, it will not use the latency data sent by the spoke.
When a spoke sends embedded health data, the hub FortiGate must be configured to receive and use it. This is done by setting set embedded-measure accept within the performance SLA configuration on the hub. This setting explicitly tells the hub to trust and use the performance metrics received from the remote FortiGate (the spoke). Without this setting, the hub will likely ignore the embedded health data and rely on its own health checks, which could lead to incorrect traffic prioritization.


質問 # 55
Within the context of SD-WAN, what does SIA correspond to?

  • A. Secure Internet Authorization
  • B. Local Breakout
  • C. Software Internet Access
  • D. Remote Breakout

正解:B


質問 # 56
......

FCSS_SDW_AR-7.4合格させる問題集でFortinet24時間で試験合格できます:https://jp.fast2test.com/FCSS_SDW_AR-7.4-premium-file.html

Fortinet FCSS_SDW_AR-7.4実際の問題とブレーン問題集:https://drive.google.com/open?id=1T44UxAD-56ItVaMc_QUCeIslQ5PRspY2


弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

我々の働いている時間: ( GMT 0:00-15:00 )
月曜日から土曜日まで

サポート: 現在連絡 

English Deutsch 繁体中文 한국어