NSE4 High Availability and Diagnostics Practice Question
A company has two FortiGate 100F units in an active-passive HA cluster with firmware version 7.2.5. The cluster is configured with session pickup and all interfaces are monitored. The network consists of three VLANs: VLAN10 (Users), VLAN20 (Servers), and VLAN30 (DMZ). The cluster is connected to two ISPs: ISP1 (port1) and ISP2 (port2). The internal network uses a single aggregated link (port3 and port4) as a LAG to the core switch. One day, the primary FortiGate experiences a hardware failure and the secondary takes over. After the primary is replaced and rejoins the cluster, the administrator notices that traffic passing through the cluster is intermittently dropping for a few seconds every minute. The administrator checks the cluster status and sees that the new primary (previously secondary) is in 'primary' state and the old primary (newly replaced) is in 'secondary' state. What is the most likely cause of the intermittent traffic drops?
⚠ Common exam trap
The trap here is that candidates often attribute intermittent traffic drops to session pickup or split-brain issues, but the key clue is the periodic nature of the drops (every minute), which points to a configuration mismatch on the aggregated link rather than a session synchronization or HA state problem.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The LAG configuration on the new FortiGate does not match the active cluster configuration.
The most likely cause is that the LAG configuration on the newly replaced FortiGate does not match the active cluster configuration. In an HA cluster, all LAG member interfaces (port3 and port4) must have identical settings—including LACP mode, speed, duplex, and VLAN membership—on both units. When the secondary FortiGate became primary and the replaced unit rejoined as secondary, any mismatch in the LAG configuration would cause the cluster to continuously renegotiate or flap the aggregated link, leading to intermittent traffic drops every few seconds as the HA cluster attempts to synchronize and stabilize the interface state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The LAG configuration on the new FortiGate does not match the active cluster configuration.
Why this is correct
In an HA cluster, all interface and link aggregation group (LAG) settings—including member ports, negotiation mode, and hashing algorithm—must be identical across both units. If the replacement FortiGate's LAG configuration differs from the active cluster configuration, the cluster members cannot synchronize interface states, resulting in link instability, frequent flapping, and interrupted traffic. Traffic drops occur because the secondary's mismatched LAG is unable to pass traffic in the same manner as the primary, violating HA consistency requirements. This matches the symptom, making it the correct root cause.
- ✗
Session pickup is not enabled on the new FortiGate.
Why it's wrong here
Session pickup is a feature that preserves existing TCP/UDP sessions when a failover occurs, but its absence does not cause continuous interface-level traffic drops. Since the cluster is operational and session pickup is confirmed to be configured and working, the secondary already carries over active sessions without interruption. A disabled session pickup would only cause transient session loss during a failover, not the persistent, intermittent traffic drop described. Therefore, the problem is not related to session pickup.
- ✗
The HA cluster is in split-brain state.
Why it's wrong here
Split-brain is a condition where both HA units independently assume the primary role because heartbeat communication fails, causing both to process traffic and create IP conflicts. The cluster status explicitly shows one primary and one secondary, proving that heartbeat and role negotiation are functioning normally. Since split-brain would display as two primary units, not a distinct primary/secondary pair, it cannot be the cause of the reported instability. Thus, this option is incorrect.
- ✗
The heartbeat interface is configured on the LAG, causing HA instability.
Why it's wrong here
Configuring the HA heartbeat interface on a LAG (link aggregation group) is an unsupported and unstable design because heartbeat packets rely on a stable, dedicated physical link for timely failover detection. If the heartbeat were on a LAG, any member link flap or aggregation renegotiation could cause HA to misinterpret peer availability and trigger unnecessary failovers. The existing note that heartbeat should not be on a LAG indicates this is not the actual configuration, and the cluster status shows a consistent primary/secondary relationship. Hence, this is not the reason for the traffic drops.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.