NSE4 High Availability and Diagnostics Practice Question
A FortiGate cluster in active-passive HA is configured with two heartbeat interfaces. The primary unit fails completely. The secondary unit detects the failure and becomes primary. After the original primary recovers, it remains in passive mode. What is the most likely reason for this behavior?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The HA override setting is disabled
When override is disabled (the default), the recovered unit will not preempt the current primary. The cluster stays with the current primary until it fails. This is the expected behavior for graceful recovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The heartbeat interfaces are not properly configured
Why it's wrong here
Heartbeat interface misconfiguration would prevent the cluster from establishing or maintaining the synchronized HA state, and symptoms would include both units acting as primary or continuous failover flaps. In this scenario, the cluster successfully failed over and the recovered unit rejoined as standby, which proves the heartbeat links and HA state synchronization are functioning correctly. Therefore, improperly configured heartbeat interfaces cannot be the reason the original primary does not reclaim its role.
- ✓
The HA override setting is disabled
Why this is correct
The HA override setting directly controls preemption after recovery: when override is disabled, a formerly failed primary that rejoins the cluster negotiates as a standby and does not force the active unit to step down, even if it has a higher configured priority. This exactly matches the described behavior of an active-passive cluster that stays with the current primary after the original primary recovers. Since override is disabled by default on FortiGate, the cluster remains in its current role assignment.
- ✗
The priority of the original primary is lower than the current primary
Why it's wrong here
Priority values only influence the initial election or preemptive takeover when override is enabled; once a failover has occurred, the current primary retains the primary role regardless of whether the recovered unit's priority is numerically higher or lower. Furthermore, for the original primary to have been active before the outage, it would normally have had the higher priority, and lowering its priority would require a configuration change that is not indicated. The lack of preemption after recovery is caused by override being disabled, not by a priority inversion.
- ✗
The HA override setting is enabled
Why it's wrong here
Enabling HA override tells the cluster to permit a recovered unit with a higher priority to preempt the current primary and resume the primary role automatically. If override were enabled in this active-passive cluster, the recovered original primary would have immediately taken back control, which is the opposite of what the scenario describes. Therefore, the only way the recovered unit remains a standby is that override is disabled, making this option incorrect.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.