View all questions & answers for the NSE 7 - Secure Networking 7.6 Architect Exam Materials exam


NSE 7 - Secure Networking 7.6 Architect Exam Materials-Question 34 Discussion
Comment Image Comment Image Comment Image

Refer to the exhibits. You are using FortiManager to manage the branch devices and configure the SD-WAN template. You update the configuration to address new user requirements and set the firewall policies shown in the second exhibit. Then, when you use the install wizard to install the updated configuration and firewall policy package on the branch devices, FortiManager reports the error shown in the third exhibit. Why can't FortiManager install the configuration on the branch devices? (Choose one answer)

  • A. You must direct traffic with the default security profile to a VPN tunnel.
  • B. You cannot install firewall policies for HTTPS traffic with no SSL inspection.
  • C. You cannot install firewall policies that reference an SD-WAN zone.
  • D. You cannot install firewall policies that reference an SD-WAN member.
Correct Answer: D

Brave-Dump Clients Votes

D 66.67%
C 33.33%

Comments



Md Nasir Uddin 2026-08-23 15:49:24

Selected Answers: C


https://community.fortinet.com/fortimanager-27/troubleshooting-tip-copy-error-due-to-a-zone-member-interface-used-in-the-policy-153770

"Once an interface is a member of a zone, that interface can't be referenced directly in a firewall policy. You have to reference the whole zone instead.
  • Ali 2026-08-30 00:35:17
    C is negating your argument as it says that you cannot use the SDWAN zone which is not correct. D is the correct answer which matches the statement in the community article stating you cannot use SD-WAN member.


Md Nasir Uddin 2026-08-23 15:50:00

Selected Answers: C


https://community.fortinet.com/fortimanager-27/troubleshooting-tip-copy-error-due-to-a-zone-member-interface-used-in-the-policy-153770

"Once an interface is a member of a zone, that interface can't be referenced directly in a firewall policy. You have to reference the whole zone instead.


Anonymous User 2026-09-02 19:51:29

Selected Answers: D


D is the correct answer which matches the statement in the community article stating you cannot use SD-WAN member.


Anonymous User 2026-09-03 23:16:15

Selected Answers: D


you can sue sdwan zone but no sdwan member


Anonymous User 2026-09-03 23:17:20

Selected Answers: D


it errored because it is using member


Anonymous User 2026-09-07 12:37:06

Selected Answers: D


Once an interface is a member of a zone, that interface can't be referenced directly in a firewall policy. You have to reference the whole zone instead.