NSE4 High Availability and Diagnostics Practice Question
A FortiGate HA cluster is configured in active-passive mode with two units. The primary unit fails. The secondary unit takes over, but some established TCP sessions are dropped. What is the most likely cause?
⚠ Common exam trap
NSE4 often tests the misconception that active-passive HA automatically preserves all sessions, when in fact session synchronization must be explicitly enabled and configured correctly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session synchronization is not enabled
In an active-passive FortiGate HA cluster, the primary unit synchronizes session state (including TCP session tables) to the secondary unit so that upon failover, established sessions can continue without interruption. If session synchronization is not enabled, the secondary unit has no knowledge of existing sessions, so when it takes over, it drops all established TCP sessions because it has no session entries for them. Thus, the most likely cause is that session synchronization is disabled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Session synchronization is not enabled
Why this is correct
Session synchronization is not enabled. In an active-passive HA cluster, the primary FortiGate maintains the complete session table for all inspected traffic. If session synchronization (or session sync) is not configured via the HA settings, the backup unit does not receive real-time updates about existing sessions. Upon failover, the newly active unit has no entries for these flows, so when endpoints continue sending packets, the FortiGate cannot match them to a session and drops them—causing established TCP connections to break and requiring applications to reconnect. This is the direct cause of the session loss observed.
- ✗
The HA failover threshold is set too high
Why it's wrong here
The HA failover threshold is set too high. The failover threshold configuration in FortiGate HA determines the conditions that trigger a failover, such as the number of failed link monitors or an interface being down, and how long those conditions must persist. Regardless of the threshold value, it has no influence on whether session state is mirrored to the backup unit; it only affects the timing and decision of the failover event. Even if the threshold is set extremely high, once failover eventually occurs, the lack of session synchronization would still cause sessions to be lost. Thus, a high threshold is not the cause of the session loss after failover.
- ✗
The HA mode is active-passive
Why it's wrong here
The HA mode is active-passive. Active-passive mode is a standard FortiGate HA configuration designed for resilience: one unit forwards traffic while the other remains in standby, ready to take over if the active unit fails. This mode does not inherently cause session loss; in fact, when combined with session synchronization, active-passive failover can preserve most established sessions seamlessly. If the HA mode were the culprit, active-active deployments would never lose sessions, but they do without session sync, and FortiGate's active-passive mode is specifically intended to maintain continuity—the mode itself is not the reason for dropped sessions.
- ✗
The heartbeat interface is down
Why it's wrong here
The heartbeat interface is down. The heartbeat (or HA management) interface is used for communication between cluster units to exchange health status and session synchronization data. If the heartbeat link goes down, the cluster may detect a communication failure and trigger a failover to ensure availability. However, the heartbeat interface being down is a possible cause of the failover event, not the reason why sessions are lost after the new unit takes over. In fact, if the heartbeat failed but session sync had been previously established, the newly active unit would already have the session table; moreover, session loss occurs specifically because session synchronization is disabled, not because the heartbeat experienced a failure.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.