Prepare for your exam certification with our FCSS_SDW_AR-7.4 Certified Fortinet
Free Fortinet FCSS_SDW_AR-7.4 Exam 2026 Practice Materials Collection
NEW QUESTION # 32
Refer to the exhibit.
The administrator used the SD-WAN overlay template to prepare an IPsec tunnels configuration for a hub- and-spoke SD-WAN topology. The exhibit shows the FortiManager installation preview for one FortiGate device.
Based on the exhibit, which statement best describes the configuration applied to the FortiGate device?
- A. It is a spoke device that establishes dynamic IPsec tunnels to the hub It can send ADVPN shortcut requests.
- B. It is a spoke device that establishes dynamic IPsec tunnels to the hub. The local subnet range is
10.10.128.0/23. - C. It is a hub device. It can send ADVPN shortcut offers.
- D. It is a hub device. It will automatically discover the spoke devices and add them to the SD-WAN topology.
Answer: C
Explanation:
The FortiManager SD-WAN overlay template preview, as described in the document, indicates:
"When the device is acting as a hub, the configuration enables the sending of ADVPN shortcut offers to spokes. This means the hub can facilitate on-demand dynamic shortcut tunnel creation between spokes, improving performance for branch-to-branch communication by bypassing the hub for inter-branch traffic after initial discovery." Such a role is critical in scalable ADVPN topologies, enabling hub devices to optimize overlays dynamically.
NEW QUESTION # 33
Refer to the exhibits. You connect to a device behind a branch FortiGate device and initiate a ping test. The device is part of the LAN subnet and its IP address is 10.0.1.101.
Based on the exhibits, which interface uses branch 1_fgt to steer the test traffic?

- A. port2
- B. port1
- C. HUB1-VPN1
- D. port4
Answer: A
Explanation:
The ping target IP 157.240.19.35 matches an App Control entry for Facebook (ID 15832).
According to the diagnose firewall route list output, this application is handled by vwl_service=2 (Non-Critical-DIA), which routes traffic via oif=4 (port2). Therefore, FortiGate steers the Facebook test traffic through port2.
NEW QUESTION # 34
SD-WAN interacts with many other FortiGate features. Some of them are required to allow SD-WAN to steer the traffic.
Which three configuration elements that you must configure before FortiGate can steer traffic according to SD-WAN rules? (Choose three.)
- A. Firewall policies
- B. Traffic shaping
- C. Interfaces
- D. Routing
- E. Security profiles
Answer: A,C,D
NEW QUESTION # 35
Refer to the exhibit.
The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths.
However, when looking at the spoke routing table, the administrator does not see the prefixes from other spokes and the additional paths Which three settings must the administrator configure inside each BGP neighbor group so spokes can learn the prefixes of other spokes and their additional paths? (Choose three.)
- A. Enable route-reflector-client.
- B. Set additional-path to send
- C. Set additional-path to forward
- D. Enable route-reflector-server
- E. Set adv-additional-path to the number of additional paths to advertise.
Answer: A,B,E
Explanation:
The hub must send additional paths to spokes (set additional-path send).
The hub must treat each spoke as a route-reflector client so spoke routes are reflected to other spokes.
The hub must specify how many additional paths to advertise (set adv-additional-path <n>).
NEW QUESTION # 36
When a customer delegate the installation and management of its SD-WAN infrastructure to an MSSP, the MSSP usually keeps the hub within its infrastructure for ease of management and to share costly resources.
In which two situations will the MSSP install the hub in customer premises? (Choose two.)
- A. The customer requires SIA with centralized breakout.
- B. The administrator expects a large volume of traffic between the branches.
- C. The majority of the branch traffic is directed to a corporate data center.
- D. The customer expects a large amount of VoIP traffic.
Answer: A,B
NEW QUESTION # 37
Refer to the exhibit. For your ZTP deployment, you review the CSV file shown in exhibit and note that it is missing important information. Which two elements must you change before you can import it into FortiManager? (Choose two.)
- A. You must define a name for each device
- B. You must define a value for each device and each metadata variable that defines an IP address.
- C. You must associate a device blueprint with each device
- D. You must define a value for each device and each user-defined metadata variable.
Answer: A,C
Explanation:
NEW QUESTION # 38
Which two statements correctly describe what happens when traffic matches the implicit SD-WAN rule?
(Choose two.)
- A. Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.
- B. The session information output displays no SD-WAN service id.
- C. FortiGate flags the session with may_dirty and vwl_def ault.
- D. Traffic does not match any of the entries in the policy route table.
- E. The traffic is distributed, regardless of weight, through all available static routes.
Answer: B,D
Explanation:
The implicit SD-WAN rule serves as the final catch-all. Per Fortinet:
"Sessions matching the implicit SD-WAN rule do not have an SD-WAN service id, as they are not associated with any specific user-defined SD-WAN rule. Additionally, this occurs only when traffic fails to match any entry in the policy route table. This default handling guarantees connectivity while minimizing the risk of blackholed traffic." Administrators can observe this in diagnostic outputs for troubleshooting.
NEW QUESTION # 39
Which three characteristics apply to provisioning templates available on FortiManager? (Choose three.)
- A. A CLI template group can contain CLI templates of both types.
- B. Each template group can contain up to three IPsec tunnel templates.
- C. CLI templates are applied in order, from top to bottom.
- D. A template group can include a system template and an SD-WAN template.
- E. A CLI template can be of type CLI script or Perl script.
Answer: A,C,D
Explanation:
Template groups can include both system and SD-WAN templates to streamline configuration deployment.
A CLI template group can include both CLI Script and CLI Snippet types.
CLI templates are applied in top-to-bottom order, which affects configuration precedence.
NEW QUESTION # 40
Refer to the exhibit. The administrator analyzed the traffic between a branch FortiGate and the server located in the data center, and noticed the behavior shown in the diagram. When the LAN clients located behind FGT1 establish a session to a server behind DC-1, the administrator observes that, on DC-1, the reply traffic is routed over T2. even though T1 is the preferred member in the matching SD-WAN rule.
What can the administrator do to instruct DC-1 to route the reply traffic through the member with the best performance?
- A. Enable snat-route-change under config system global.
- B. FortiGate route lookup for reply traffic only considers routes over the original ingress interface.
- C. Enable reply-session under config system sdwan.
- D. Enable auxiliary-session under config system settings.
Answer: D
Explanation:
To ensure DC-1 responds via the best-performing SD-WAN member (T1) instead of defaulting to T2, enable auxiliary-sessionunder config system settings, so reply traffic is evaluated against current route policies-not bound to the ingress interface.
NEW QUESTION # 41
Refer to the exhibits.

The interface details, static route configuration, and firewall policies on the managed FortiGate device are shown.
You want to configure a new SD-WAN zone, named Underlay, that contains the interfaces port1 and port2.
What must be your first action?
- A. Define port1 as an SD-WAN member.
- B. Delete the firewall policies.
- C. Delete the SD-WAN Zone Test.
- D. Delete the static routes.
Answer: D
Explanation:
In the exhibits, port2 is already assigned to the SD-WAN zone named Test. An interface can only belong to a single SD-WAN zone, so before you can add both port1 and port2 into the new SD-WAN zone Underlay, you must first delete the SD-WAN Zone Test to free port2.
NEW QUESTION # 42
Refer to the exhibit. Which statement best describe the role of the ADVPN device in handling traffic?
- A. This is a hub that has received a shortcut query from a spoke and has forwarded it to another spoke.
- B. This is a spoke that has received a shortcut query from a remote hub.
- C. This is a hub, and two spokes, 192.2.0.1and 10.0.3.101, establish a shortcut.
- D. This is a spoke that has received a direct shortcut query from a remote spoke.
Answer: A
Explanation:
NEW QUESTION # 43
Refer to the exhibit.
The exhibit shows output of the command diagnose sys adwan aervice4 collected on a FortiGate device.
The administrator wants to know through which interface FortiGate will steer traffic from local users on subnet 10.0.1.0/255.255.255.192 and with a destination of the social media application Facebook.
Based on the exhibits, which two statements are correct? (Choose two.)
- A. When FortiGate cannot recognize the application of the flow, it steers the traffic through the preferred member of rule 3, HQ_T1.
- B. When FortiGate cannot recognize the application of the flow, it load balances the traffic through the tunnels HQ_T1. HQ_T2. HQ_T3.
- C. FortiGate steers traffic for social media applications according to the service rule 2 and steers traffic through port2.
- D. There is no service defined for the Facebook application, so FortiGate appliesservice rule 3 and directs the traffic to headquarters.
Answer: B,C
NEW QUESTION # 44
Refer to the exhibits. You use FortiManager to configure SD-WAN on three branch devices.
When you install the device settings. FortiManager prompts you with the error "Copy Failed" for the device branch1_fat When you click the log button. FortiManager displays the message shown in the exhibit.
Based on the exhibits, which statement best describes the issue and how you can resolve it?


- A. Check the metadata variable definitions, and review the per-device mapping configuration.
- B. Gateways for all members in a zone must be defined the same way. Specify the gateway of the SD-WAN member port! without metadata variables.
- C. Remove the installation target for the SD-WAN member port4. You cannot combine metadata variable and installation targets.
- D. Check the connection between branch1_fgt and FortiManager
Answer: A
Explanation:
The error message clearly states invalid ip addr for the metadata variable ${sdwan_port1_gw}, which means the per-device value for this variable is not defined or is incorrectly mapped. You must verify the metadata mapping for branch1_fgt to ensure that ${sdwan_port1_gw} is assigned a valid IP address.
NEW QUESTION # 45
Refer to the exhibit.
Refer to the exhibit.
You want to configure SD-WAN on a network as shown in the exhibit.
The network contains many FortiGate devices. Some are used as NGFW, and some are installed with extensions such as FortiSwitch. FortiAP. or Forti Ex tender.
What should you consider when planning your deployment?
- A. You can build an SD-WAN topology that includes all devices. The hubs can be FortiGate devices with Forti Extender.
- B. You must build multiple SD-WAN topologies. Each topology must contain only one type of extension.
- C. You must use FortiManager to manage your SD-WAN topology.
- D. You can build an SD-WAN topology that includes all devices. The hubs must be devices without extensions.
Answer: D
NEW QUESTION # 46
Exhibit.
Refer to the exhibit, which shows the SD-WAN rule status and configuration.
Based on the exhibit, which change in the measured packet loss will make HUB1-VPN3 the new preferred member?
- A. When all three members have the same packet loss
- B. When HUB1-VPN3 has 4% packet loss
- C. When HUB1-VPN1 has 4% packet loss
- D. When HUB1-VPN1 has 12% packet loss
Answer: D
NEW QUESTION # 47
Refer to the exhibit that shows a diagnose output on FortiGate.
Based on the output shown in the exhibit, what can you say about the device role and how it handles health checks?
- A. The device is a hub. It receives health-check measures for the tunnels of a spoke.
- B. The device is a spoke. It receives health-check measures for the tunnels of another spoke.
- C. The device is a spoke. It provides embedded health-check measures for each tunnel to the hub.
- D. The device is a hub. It receives embedded health-check measures for each tunnel from the spoke.
Answer: B
Explanation:
NEW QUESTION # 48
......
Pass Fortinet FCSS_SDW_AR-7.4 Actual Free Exam Q&As Updated Dump: https://www.prep4sureguide.com/FCSS_SDW_AR-7.4-prep4sure-exam-guide.html
FCSS_SDW_AR-7.4 Exam Info and Free Practice Test All-in-One Exam Guide Apr-2026: https://drive.google.com/open?id=1ceRVFKY9vxPU0SHxp1vYISn1JAAEhTvO