Q: 10
Refer to the exhibit.
The exhibit shows output of the command diagnose sys adwan aervice4 collected on a FortiGate
device.
The administrator wants to know through which interface FortiGate will steer traffic from local users
on subnet 10.0.1.0/255.255.255.192 and with a destination of the social media application Facebook.
Based on the exhibits, which two statements are correct? (Choose two.)
The exhibit shows output of the command diagnose sys adwan aervice4 collected on a FortiGate
device.
The administrator wants to know through which interface FortiGate will steer traffic from local users
on subnet 10.0.1.0/255.255.255.192 and with a destination of the social media application Facebook.
Based on the exhibits, which two statements are correct? (Choose two.)Options
Discussion
Pretty sure C and D, B tries to catch you if you forget app matching is before service checks.
Probably C and D, unless the app ID for Facebook changes or rule priorities are tweaked in config.
B tbh
C/D? Traffic for Facebook hits the app-based rule (service rule 4), so it'd use port2 since that's set as higher priority, I think. If the app's not detected, FortiGate falls back to implicit load balancing over all members. Not 100% sure-anyone spot something off in the exhibit?
Seriously wish Fortinet would make SD-WAN rule wording less confusing, but it's C and D.
Option C and D for sure. B is a bit of a trap since Facebook does match the application ID, so it won't just default to rule 3. Saw similar wording in other practice sets, pretty sure this is what FortiGate does. Disagree?
B , since if there’s no defined service for Facebook, the traffic might follow default handling. Could be missing something in the SD-WAN rule match though-anyone cross-check in the exam guide or with labs?
I don't think it's B here. C and D are correct, since B overlooks how the fallback/implicit SD-WAN rule works. The trap is thinking there's no service for Facebook, but the rule matching on app ID catches it first. Others agree?
C and D tbh
Has anyone checked this against the official admin guide or done a lab? Practice exams seem to line up with C and D but would be good to double check with Fortinet's docs for these SD-WAN rule behaviors.
Be respectful. No spam.