[2026年01月02日] 完全版最新のFCSS_SDW_AR-7.6問題集で100%カバー率問題と解答があなたをリアル試験で合格させる
最新FCSS_SDW_AR-7.6試験問題集で有効最新の問題集
質問 # 29
You have a FortiGate configuration with three user-defined SD-WAN zones and two members in each of these zones. One SD-WAN member is no longer in use in health-check and SD-WAN rules. You want to delete it.
What happens if you delete the SD-WAN member from the FortiGate GUI?
- A. FortiGate displays an error message. You must use the CLI to delete an SD-WAN member.
- B. FortiGate accepts the deletion and places the member in the default SD-WAN zone.
- C. FodiGate accepts the deletion and removes routes as required.
- D. FortiGate displays an error message. SD-WAN zones must contain at least two members
正解:C
解説:
In FortiOS, you can remove an SD-WAN member from the GUI as long as it is not in use in any health-checks, SD-WAN rules, or policies.
When you delete it, FortiGate will automatically clean up related routes (static or dynamic SD- WAN routes referencing that member).
質問 # 30
You have a FortiGate configuration with three user-defined SD-WAN zones and two members in each of these zones. One SD-WAN member is no longer in use in health-check and SD-WAN rules. You want to delete it.
What happens if you delete the SD-WAN member from the FortiGate GUI?
- A. FortiGate displays an error message. You must use the CLI to delete an SD-WAN member.
- B. FortiGate accepts the deletion and places the member in the default SD-WAN zone.
- C. FodiGate accepts the deletion and removes routes as required.
- D. FortiGate displays an error message. SD-WAN zones must contain at least two members
正解:C
解説:
In FortiOS, you can remove an SD-WAN member from the GUI as long as it is not in use in any health-checks, SD-WAN rules, or policies.
When you delete it, FortiGate will automatically clean up related routes (static or dynamic SD- WAN routes referencing that member).
質問 # 31
When you configure FortiGate for SD-WAN, what is the impact when you assign a priority to the SD-WAN members?
- A. It is used by the SD-WAN rules configured with the manual strategy to determine the preferred member when all are alive.
- B. It is used to prioritize one static route over another in the case of ECMP routes.
- C. It is used by the SD-WAN rules configured with the lowest cost strategy to select between members with similar performances.
- D. It is used by SD-WAN rules that allow load balancing to determine the proportion of traffic steered to each link.
正解:B
解説:
SD-WAN priority acts similarly to static route priority. It is used to assign an order of preference among SD-WAN members and affects routing decisions including static routes under ECMP scenarios.
質問 # 32
You manage an SD-WAN topology. You will soon deploy 50 new branches.
Which three tasks can you do in advance to simplify this deployment? (Choose three.)
- A. Create model devices.
- B. Update the DHCP server configuration.
- C. Create policy blueprint.
- D. Create a ZTP template.
- E. Define metadata variables value for each device.
正解:A、D、E
解説:
These tasks facilitate automated and standardized configuration and provisioning of devices for the new branches, reducing manual effort during deployment. Creating model devices allows reusable configurations, the ZTP template enables automatic device onboarding without on-site IT, and defining metadata variables customizes device parameters per branch in advance.
質問 # 33
You configured an SD-WAN rule with the best quality strategy and selected the predefined health check, Default_FortiGuard, to check the link performances against FortiGuard servers.
For the quality criteria, you selected Custom-profile-1.
Which factors does FortiGate use, and in which order. to determine the link that it should use to steer the traffic?
- A. Links that meet the SLA targets - Member configuration order - Member local cost
- B. Latency - Member configuration order - Link cost threshold
- C. Link quality index - Member configuration order - Link cost threshold
- D. Latency - Jitter - Packet loss - Bibandwidth - Member configuration order
正解:C
解説:
FortiGate determines the member with the best quality using three factors: member configuration order, the link-cost-threshold setting, and the value of the metric measured for the member.
質問 # 34
Refer to the exhibit. The administrator used the SD-WAN overlay template to prepare an IPsec tunnels configuration for a hub-and-spoke SD-WAN topology. The exhibit shows the FortiManager installation preview for one FortiGate device.
Based on the exhibit, which statement best describes the configuration applied to the FortiGate device?
- A. It is a spoke device that establishes dynamic IPsec tunnels to the hub It can send ADVPN shortcut requests.
- B. It is a spoke device that establishes dynamic IPsec tunnels to the hub. The local subnet range is
10.10.128.0/23. - C. It is a hub device. It can send ADVPN shortcut offers.
- D. It is a hub device. It will automatically discover the spoke devices and add them to the SD-WAN topology.
正解:C
解説:
The phase1-interface shows set type dynamic, set peertype any, and set mode-cfg enablewith an address pool (ipv4-start-ip, ipv4-end-ip, ipv4-netmask). Those are dial-up server settings-i.e., a hub handing out virtual IPs to spokes. It also has set auto- discovery-sender enable, allowing the hub to participate in ADVPN shortcut negotiation (sending offers).
質問 # 35
You are planning a new SD-WAN deployment with the following criteria:
- Two regions
- Most of the traffic is expected to remain within its region
- No requirement for inter-region ADVPN
To remain within the recommended best practices, which routing protocol should you select for the overlays?
- A. IBGP with BGP on loopback within each region and EBGP between the regions.
- B. IBGP within each region and between the regions.
- C. OSPF for the routing within each region and EBGP between the regions.
- D. IBGP with BGP per overlays within each region and IBGP with BGP on loopback between the regions.
正解:A
解説:
Using iBGP with BGP on loopback within each region ensures scalable and stable routing inside the region, while eBGP between regions aligns with best practices to maintain clear boundaries, reduce convergence complexity, and support region separation.
質問 # 36
SD-WAN interacts with many other FortiGate features. Some of them are required to allow SD- WAN to steer the traffic.
Which three configuration elements that you must configure before FortiGate can steer traffic according to SD-WAN rules? (Choose three.)
- A. Traffic shaping
- B. Interfaces
- C. Firewall policies
- D. Security profiles
- E. Routing
正解:B、C、E
解説:
Interfaces must be defined and added as SD-WAN members to participate in traffic steering.
Routing is required so FortiGate knows how to reach destinations through SD-WAN paths.
Firewall policies are needed to permit traffic and allow SD-WAN rules to take effect.
質問 # 37
Refer to the exhibits. The interface details, static route configuration, and firewall policies on the managed FortiGate device are shown.
You want to configure a new SD-WAN zone, named Underlay, that contains the interfaces port1 and port2.
What must be your first action?

- A. Delete the static routes.
- B. Define port1 as an SD-WAN member.
- C. Delete the SD-WAN Zone Test.
- D. Delete the firewall policies.
正解:D
解説:
You cannot add port1 as an SD-WAN member if it's already in use by an active firewall policy.
質問 # 38
Refer to the exhibits.
Exhibit A
Exhibit B
Exhibit A shows a policy package definition. Exhibit B shows the install log that the administrator received when he tried to install the policy package on FortiGate devices.
Based on the output shown in the exhibits, what can the administrator do to solve the issue?
- A. Policies can refer to only one LAN source interface. Keep only the D-LAN, which is the dynamic LAN interface.
- B. Create dynamic mapping for the LAN interface for all devices in the installation target list.
- C. Use a metadata variable instead of a dynamic interface to define the firewall policy.
- D. Dynamic mapping should be done automatically. Review the LAN interface configuration for branch2_fgt.
正解:B
質問 # 39
Refer to the exhibits, which show the configuration of an SD-WAN rule and the corresponding rule status and routing table.

The administrator wants to understand the expected behavior for traffic matching the SD-WAN rule.
Based on the exhibits, what can the administrator expect for traffic matching the SD-WAN rule?
- A. The traffic will be routed over HUB1-VPN3.
- B. The traffic will be routed over HUB1-VPN2
- C. The traffic will be routed over HUB1-VPN1.
- D. The traffic will be load balanced across all three overlays
正解:B
解説:
The rule is in SLA mode with two SLAs. From the status, HUB1-VPN2 and HUB1-VPN3 meet the SLA (sla(0x2) and sla(0x3)), while HUB1-VPN1 does not (sla(0x0)). Among members that meet SLA, FortiGate uses the configured order (priority-members 4 5 6) to pick the first eligible one- HUB1-VPN2-so traffic is routed over HUB1-VPN2.
質問 # 40
You used the HUB IPsec_Recommended and the BRANCH IPsec_Recommended templates to define the overlay topology. Then, you used the SD-WAN template to define the SD- WAN members, rules, and performance SLAs.
You applied the changes to the devices and want to use the FortiManager monitors menu to get a graphical view that shows the status of each SD-WAN member.
Which statement best explains how to obtain this graphical view?
- A. Use the SD-WAN monitor table view to get a donut view and a table view that shows the status of each SD-WAN member, including the SLA pass or missed status.
- B. Use the SD-WAN monitor template view to get a map view of the branches, hub, and tunnel status, including the SLA pass or missed status.
- C. Use the VPN monitor map view to get a map view of the branches, hub, and tunnel status, including the SLA pass or missed status.
- D. Use the SD-WAN monitor asset view to get a donut view and a table view that shows the status of each device and the SLA status of each SD-WAN member.
正解:A
解説:
The SD-WAN monitor's table view in FortiManager provides a donut visualization plus a detailed table that shows each SD-WAN member's status and SLA pass/miss, giving the per-member health view you're after.
質問 # 41
Refer to the exhibits. You connect to a device behind a branch FortiGate device and initiate a ping test. The device is part of the LAN subnet and its IP address is 10.0.1.101.
Based on the exhibits, which interface uses branch 1_fgt to steer the test traffic?

- A. port2
- B. port4
- C. HUB1-VPN1
- D. port1
正解:A
解説:
The ping target IP 157.240.19.35 matches an App Control entry for Facebook (ID 15832).
According to the diagnose firewall route list output, this application is handled by vwl_service=2 (Non-Critical-DIA), which routes traffic via oif=4 (port2). Therefore, FortiGate steers the Facebook test traffic through port2.
質問 # 42
You are planning a large SD-WAN deployment with approximately 1000 spokes and want to allow ADVPN between the spokes. Some remote sites use FortiSASE to connect to the company's SD- WAN hub. Which overlay routing configuration should you use?
- A. BGP on loopback with dynamic BGP for ADVPN shortcut routing.
- B. BGP on loopback with IPsec phase2 selectors for ADVPN shortcut routing.
- C. BGP per overlay with BGP next-hop convergence for ADVPN shortcut routing.
- D. BGP per overlay with dynamic BGP for ADVPN shortcut routing.
正解:A
解説:
Using BGP on loopback with dynamic BGP enables scalable routing for large deployments and supports ADVPN shortcut routing with resilient, stable next-hop reachability across dynamic tunnels.
質問 # 43
Refer to the exhibits. The exhibits show the configuration for SD-WAN performance. SD-WAN rule, the application IDs of Facebook and YouTube along with the firewall policy configuration and the underlay zone status. Which two statements are true about the health and performance of SD-WAN members 3 and 4? (Choose two.)

- A. The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.
- B. Only related TCP traffic is used for performance measurement.
- C. FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.
- D. Encrypted traffic is not used for the performance measurement.
正解:A、B
解説:
Based on the SD-WAN configuration exhibit for health checks and service with application IDs for Facebook (15832) and YouTube (31077) and health-check set to "Passive" mode for members 3 and 4, the following conclusions about the health and performance of SD-WAN members 3 and 4 are true:
Only related TCP traffic is used for performance measurement
The passive health-check mode measures performance based on real application traffic, which generally includes TCP traffic affecting the monitored applications.
The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member The configured service includes both Facebook and YouTube app IDs, and performance measurement aggregates data from these applications.
質問 # 44
Refer to the exhibit. Which SD-WAN rule and interface uses FortiGate to steer the traffic from the LAN subnet 10.0.1.0/24 to the corporate server 10.2.5.254?
- A. SD-WAN service rule 4 and port1 or port2.
- B. SD-WAN service rule 3 and interface HUB1-VPN3.
- C. SD-WAN service rule 4 and interface port2.
- D. SD-WAN service rule 3 and interface HUB1-VPN2.
正解:B
解説:
First off, the traffic matches the SD-WAN rule with service ID 3. We can see that there is at least one valid route in the FIB, so the SD-WAN rule will be selected.
Next, we see HUB1-VPN2 and HUB1-VPN3 have the same slamap value of 0x1 - therefore, they are equally valid members to choose from, and a tiebreak occurs (since there is no load balancing configured).
Looking at the routes, HUB1-VPN3 has a more SPECIFIC route (i.e. better route) and therefore, it wins the tiebreak.
質問 # 45
An administrator is configuring SD-WAN to load balance their network traffic. Which two things should they consider when setting up SD-WAN? (Choose two.)
- A. When applicable, FortiGate load balances the traffic through all members that meet the SLA target.
- B. SD-WAN load balancing is possible only using the best quality and lowest cost (SLA) strategies.
- C. Only the manual and best-quality strategies allow SD-WAN load balancing.
- D. You can select the outbandwidth hash mode with all strategies that allow load balancing.
正解:A、D
解説:
FortiGate load balances traffic across all members that meet the SLA targets, depending on the strategy used.
The outbandwidth hash mode can be selected with load-balancing strategies to distribute traffic based on flow characteristics.
質問 # 46
Within the context of SD-WAN, what does SIA correspond to?
- A. Secure Internet Authorization
- B. Local Breakout
- C. Software Internet Access
- D. Remote Breakout
正解:D
解説:
質問 # 47
An SD-WAN member is no longer used to steer SD-WAN traffic. The administrator updated the SD-WAN configuration and deleted the unused member. After the configuration update, users report that some destinations are unreachable. You confirm that the affected flow does not match an SD-WAN rule.
What could be a possible cause of the traffic interruption?
- A. FortiGate can remove some static routes associated with an interface when the member is removed from SD-WAN.
- B. FortiGate removes the layer 3 settings for interfaces that are removed from the SD-WAN configuration.
- C. FortiGate, with SD-WAN enabled, cannot route traffic through interfaces that are not SD-WAN members.
- D. FortiGate administratively brings down interfaces when they are removed from the SD-WAN configuration.
正解:A
解説:
When an SD-WAN member is deleted, FortiGate can also remove static routes that were tied to that interface. If those routes are needed for destinations not covered by SD-WAN rules, traffic to those networks becomes unreachable. This explains why flows not matching SD-WAN rules are interrupted after the member was removed.
質問 # 48
As an MSSP administrator, you are asked to configure ADVPN on an existing SD-WAN topology.
FortiManager manages the customer devices in a dedicated ADOM. The previous administrator used the SD-WAN overlay topology.
Which two statements apply to this scenario? (Choose two.)
- A. After you enable auto-discovery VPN in the overlay template, you must select between ADVPN
2.0 and ADVPN 1.0. - B. You can activate auto-discovery VPN in the SD-WAN overlay template for any type of topology, including a primary-primary dual-hub topology.
- C. You can activate auto-discovery VPN in the SD-WAN overlay template only if it is a single hub topology.
- D. When auto-discovery VPN is enabled, FortiManager updates the IPsec and BGP templates in the hub.
正解:B、D
解説:
When you enable ADVPN (auto-discovery VPN) in the overlay template, FortiManager automatically updates both the IPsec and BGP templates on the hub so that shortcut tunnels can be established dynamically.
ADVPN can be activated in the SD-WAN overlay template for any supported topology, including dual-hub primary-primary, not just single hub.
質問 # 49
Which two statements are correct when traffic matches the implicit SD-WAN rule? (Choose two.)
- A. Traffic does not match any of the entries in the policy route table.
- B. Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.
- C. The session information output displays no SD-WAN-specific details.
- D. All SD-WAN rules have the default and gateway setting enabled.
正解:A、C
解説:
If the session matched the SD-WAN implicit rule, and therefore was handled using standard FIB routing, these SD-WAN fields do not appear.
If traffic doesnt match any entry in the proute table then it will use the implicity deny SD-WAN rule.
質問 # 50
Refer to the exhibit that shows an SD-WAN zone configuration on the FortiManager GUI.
Based on the exhibit, how will the FortiGate device behave after it receives this configuration?
- A. The configuration instructs FortiGate to allow ADVPN shortcuts for the tunnels of this SD-WAN zone.
- B. The configuration instructs FortiGate to choose an ADVPN shortcut based on SD-WAN information.
- C. The configuration instructs FortiGate to establish shortcuts only for overlay interfaces that meet the SLA target HUB1_HC.
- D. The configuration instructs FortiGate to establish shortcuts only when at least two members meet the SLA target.
正解:D
解説:
This is because the setting minimum-sla-meet-members = 2 requires at least two SD-WAN zone members (in this case, HUB2-VPN1, HUB2-VPN2, and HUB2-VPN3) to pass the defined SLA health check (HUB1_HC) before the FortiGate will establish ADVPN shortcuts. If fewer than two members meet the SLA, shortcuts will not be created.
質問 # 51
Refer to the exhibit, which shows an SD-WAN zone configuration on the FortiGate GUI. What can you conclude about the zone and member configuration on this device?
- A. The overlay-factories zone contains no member.
- B. The underlay zone contains three members.
- C. You can delete the virtual-wan-link zones.
- D. You can move HUB1-VPN3 from the HUB1 zone to the overlay-shops zone.
正解:D
解説:
The VPN members under HUB1 (HUB1-VPN1, HUB1-VPN2, HUB1-VPN3) are all SD-WAN interfaces that can be reassigned to a different zone, such as overlay-shops. FortiGate allows reassigning members between zones.
質問 # 52
......
無料セールまもなく終了!100%有効なFCSS_SDW_AR-7.6試験:https://www.passtest.jp/Fortinet/FCSS_SDW_AR-7.6-shiken.html
検証済みFCSS_SDW_AR-7.6試験解答合格確定させる:https://drive.google.com/open?id=1kdpyoxhDQq9vtmaqO5ZPr6TcEwf0cMpF