# NSE7_SDW-72 — Question 425

**Type:** multiple_response
**Topics:** topic_1

## Question

Refer to the exhibits.
Exhibit A.
//IMG//

Exhibit B.
//IMG//

An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in exhibit A.
After generating GoToMeeting test traffic, the administrator examined the respective traffic log on FortiAnalyzer, which is shown in exhibit B. The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.
Which two reasons explain why some log messages show that the traffic matched the implicit SD-WAN rule? (Choose two.)

## Correct Answer

_See scenario._

## Explanation

Selected Answer: BD
B: There is no 3-tuple with IP 23.212.248.205

D: Page 156 of the study guide. "By default, SNAT sessions are not flagged as dirty following a routing change that impacts the session". So, the first routing match is the default sd wan rule. After identifying the app, the match is now rule ID 1. However, because there is SNAT to the Internet, the session is not marked as "dirty". It is not re-evaluated and traffic keeps going through port2.

**Reference:** examtopics_top_comment

---
Source: https://hiexam.net/q/fortinet/NSE7_SDW-72/425  
Practice (tracked): https://hiexam.net/study/NSE7_SDW-72/practice