1. Fortinet FortiOS 7.6.0 SD-WAN Administration Guide, Local-out traffic, Page 101.
The document states, "By default, local-out traffic from the FortiGate does not use SD-WAN rules for routing. You must enable SD-WAN for each service that you want to use SD-WAN." This directly supports answers B and D.
2. Fortinet FortiOS 7.6.0 CLI Reference, config system dns, Page 1038.
The set sdwan-zone command under config system dns is an example of the per-service configuration required, which supports answer D. It shows that DNS, as a specific local-out service, must be individually configured.
3. Fortinet FortiOS 7.6.0 CLI Reference, config system fortiguard, Page 1101.
Similar to the DNS configuration, the set sdwan-zone command under config system fortiguard demonstrates the requirement to enable SD-WAN for another specific local-out service (FortiGuard), reinforcing answer D.