exam questions

Exam NSE7_SDW-7.2 All Questions

View all questions & answers for the NSE7_SDW-7.2 exam

Exam NSE7_SDW-7.2 topic 1 question 5 discussion

Actual exam question from Fortinet's NSE7_SDW-7.2
Question #: 5
Topic #: 1
[All NSE7_SDW-7.2 Questions]

Refer to the exhibit.

The exhibit shows output of the command diagnose sys sdwan service collected on a FortiGate device.
The administrator wants to know through which interface FortiGate will steer the traffic from local users on subnet 10.0.1.0/255.255.255.192 and with a destination of the business application Salesforce located on HQ servers 10.0.0.1.
Based on the exhibits, which two statements are correct? (Choose two.)

  • A. There is no service defined for the Salesforce application, so FortiGate will use the service rule 3 and steer the traffic through interface T_HQ1.
  • B. FortiGate steers traffic to HQ servers according to service rule 1 and it uses port1 or port2 because both interfaces are selected.
  • C. When FortiGate cannot recognize the application of the flow it steers the traffic destined to server 10.0.0.1 according to service rule 3.
  • D. FortiGate steers traffic for business application according to service rule 2 and steers traffic through port2.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ee0808
Highly Voted 1 year, 5 months ago
C & D Salesforce = Business category -> D is correct C is a general rule
upvoted 14 times
theklee
9 months, 1 week ago
Yes, Salesforce = business category, but the service sd-wan service 3 rule says "Internet Services" which are application specific. If they wanted to catch Salesforce as a business application, the rule should say Application Control instead of Internet Service.
upvoted 1 times
BoostBoris
5 months ago
Just tested on my FGT v7.2.10. When you configure SD-WAN rule with application "business" and "industrial", command diag sys sdwan service returns "Internet Service(2): Business(0,29,0,0,0) Industrial(0,26,0,0,0)"
upvoted 1 times
...
...
...
fa7474b
Most Recent 3 months, 3 weeks ago
Selected Answer: AC
D is incorrect, the ISDB uses public IP addresses. The question is about "salesforce located on HQ Servers 1 Therefore A is correct because there is no definition for THEIR particular flavor of salesfore traffic. C is also correct.
upvoted 3 times
...
djekson
4 months, 3 weeks ago
Selected Answer: AC
D is not correct because ISDBs are public IPs, not 10.0.0.1
upvoted 4 times
...
mader
5 months, 1 week ago
Selected Answer: C
C is correct D is incorrect - The Internet Service Database is public IP address database that comes from the FortiGuard service system. The server define with private IP located at HQ, which is unlikely to be recognized by FortiGuard
upvoted 1 times
BoostBoris
5 months ago
It is not Internet Service configured in SD-WAN rule, it is Application. Salesforce is part of Business category. diag sys sdwan service outputs showing "Internet Service" can be confusing
upvoted 1 times
...
...
Slikings
6 months, 2 weeks ago
Selected Answer: CD
Answers C and D are correct A: is incorrect because, there is a service defined for salesforce. It is considered under the category of business rather than the application specifically being called out. B: is incorrect because, there is no correlation between the application ID and the interface it is coming out from other than the source address. C: is correct because, it could use rule 3 if it did not have the category already selected in rule 2. However, if the service was not defined in service 2 it would use 3 D: is correct because, service (2) uses port 2 and the application ID falls into the business category.
upvoted 1 times
...
cannoe
7 months ago
Selected Answer: AD
Option C oversimplifies the process. When Fortigate cannot recognize the application, FortiGate will try to match the traffic based on the available rules. Rule 3 is chosen when no other specific rules match the traffic due to the default fallback behavior. For me, C is incorrect since it suggests that Rule 3 is selected only when Fortigate cannot recognize the application.
upvoted 1 times
...
theklee
9 months, 2 weeks ago
In terms of sdwan service, Business is an application category, not an Internet Service. The Salesforce application is an internet service. At least in 7.4.5. Therefore A is correct - no service is defined for Salesforce and C is also correct. D would be correct if the diag sys sdwan service showed Application Control: Business but it shows Internet Service instead.
upvoted 1 times
...
ccie8122
9 months, 3 weeks ago
Selected Answer: CD
A is incorrect because Salesforce is in category Business and with the matching source IP address, the traffic will match Service 2, thus making D correct. C is correct as a general catch-all rule logic (absent application matching)--even though not applicable as the application does match in this case.
upvoted 1 times
...
rac_sp
10 months, 3 weeks ago
Selected Answer: CD
Guys I just confirmed in the Fortiguard Labs that the Sales Force traffic belongs to the category BUSINESS. Therefore, answer is C and D
upvoted 1 times
...
evdw
11 months, 3 weeks ago
Selected Answer: CD
rule 2 match is not based ISDB but on application category (category 29 = Business) If Application Control is activated on the security policy, traffic can be matched and sdwan service rule can be matched So I would go for C,D
upvoted 2 times
...
geroboamo
11 months, 3 weeks ago
Selected Answer: AC
the question states that salesforce is hosted on a private server, so sdwan rule 2 is not matched since it uses Internet Services DataBase. So traffic will be managed by rule 3
upvoted 4 times
...
luismanzanero
1 year ago
Selected Answer: CD
C & D are correcte
upvoted 1 times
...
fottyfan
1 year, 1 month ago
Question is, would Salesforce traffic be recognized if it is to private servers?
upvoted 3 times
...
tibrad4
1 year, 2 months ago
Selected Answer: CD
C&D I originally thought A and C but after looking at it this question is very misleading. Answer D is not saying that the specific server traffic is going to use port2, it is saying Salesforce traffic will use it. Since Salesforce is in the business category, A becomes invalid and D becomes true.
upvoted 1 times
...
sugar12
1 year, 2 months ago
Selected Answer: CD
A is wrong because Salesforce is part of the business category B is wrong because rule 1 doesnt cover salesforce therefore C & D are correct
upvoted 1 times
...
VLAN_G
1 year, 3 months ago
Selected Answer: CD
CD for sure.
upvoted 2 times
...
truserud
1 year, 3 months ago
Selected Answer: CD
Forgot to mark answers. See my other comment below.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...