About the Exam

This exam covers Fortinet Secure SD-WAN deployment scenarios, centralized configuration, monitoring, and troubleshooting. It is intended for network and security professionals responsible for designing, administering, and supporting Fortinet SD-WAN environments. Passing demonstrates applied capability with Fortinet SD-WAN operations in an enterprise setting.

Exam Topics

  • Enterprise Networking0–34%
  • Network Security0–33%
  • SD-WAN33%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 6, 2026 at 4:53 AM

Topic filter
Retired questions
Question sort

QuestionQ1

Enterprise Networking

Which diagnostic command can be used to display the member utilization statistics measured by performance SLAs during the last 10 minutes?

  • A diagnose sys sdwan intf-sla-log
  • B diagnose sys sdwan health-check
  • C diagnose sys sdwan log
  • D diagnose sys sdwan sla-log
Explanation

diagnose sys sdwan sla-log displays the stored Performance SLA health-check measurements for a specified SLA and SD-WAN member over the last 10 minutes. Fortinet’s CLI reference describes this command as showing health-check quality information for that period. FortiGate CLI reference — diagnose sys

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Network Security

Which two protocols in the IPsec suite are most commonly used for authentication and encryption?

Choose two
  • A Encapsulating Security Payload (ESP)
  • B Secure Shell (SSH)
  • C Internet Key Exchange (IKE)
  • D Security Association (SA)
Explanation

Encapsulating Security Payload (ESP) protects IPsec traffic with confidentiality, authentication, integrity, and anti-replay capabilities. Internet Key Exchange (IKE) establishes authenticated keying material and negotiates the security associations that define IPsec protection. A security association is a negotiated set of security parameters, not a protocol, and SSH is separate from IPsec.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Enterprise Networking

Which two settings can be configured to accelerate routing convergence in BGP?

Choose two
  • A update-source
  • B set-route-tag
  • C holdtime-timer
  • D link-down-failover
Explanation

A shorter BGP hold-time timer detects an unresponsive BGP peer sooner, and link-down failover tears down affected BGP peer relationships promptly when the underlying link fails. Both reduce the time required to withdraw routes and converge after a failure.

Community Discussion

No comments yet. Be the first to start the discussion!

Which two statements are true when traffic matches the implicit SD-WAN rule?

Choose two
  • A The sdwan_service_id flag in the session information is 0.
  • B All SD-WAN rules have the default setting enabled.
  • C Traffic does not match any of the entries in the policy route table.
  • D Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.
Explanation

The implicit SD-WAN rule is used only after traffic fails to match a user-defined policy-route entry and is forwarded through normal FIB routing. Its session record uses sdwan_service_id=0 in FortiOS versions that display this field. SD-WAN-enabled devices use the SD-WAN load-balance-mode setting rather than v4-ecmp-mode for this behavior.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

Which two statements concerning SD-WAN central management are correct?

Choose two
  • A The objects are saved in the ADOM common object database.
  • B It does not support meta fields.
  • C It uses templates to configure SD-WAN on managed devices.
  • D It supports normalized interfaces for SD-WAN member configuration.
Explanation

FortiManager central SD-WAN management stores its shared objects in the ADOM common object database and uses SD-WAN templates to configure and deploy settings to managed FortiGate devices. In this feature set, SD-WAN templates support Device VDOM meta fields but do not support normalized interfaces for SD-WAN member configuration; members are bound by name to physical or VPN interfaces.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home