Courseiva

NSE4 System and Network Administration Practice Question

A FortiGate in HA active-passive cluster is experiencing failover events. The administrator runs 'get system ha status' and sees that the 'sync status' is 'out of sync'. What is the most likely cause?

⚠ Common exam trap

A common mix-up: candidates confuse 'session synchronization' with 'configuration synchronization' and assume that disabling session sync (Option B) would cause the 'sync status' to show 'out of sync', but the command output specifically reflects configuration sync status, not session sync.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The passive unit has a different firmware version.

In an HA active-passive cluster, the 'sync status' indicates whether configuration and session data are synchronized between the primary and secondary units. When the passive unit has a different firmware version, the FortiGate cannot synchronize its configuration or sessions because the data structures and features may differ between versions, leading to an 'out of sync' status. This is a common prerequisite: both units must run the exact same firmware image for HA synchronization to function.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The HA mode is set to active-active.

    Why it's wrong here

    The cluster is explicitly identified as active-passive, so an active-active HA mode would contradict the premise and alter the failover model entirely. Even if the mode were somehow set to active-active, FGCP requires both units to use the identical HA mode; a mismatch would prevent the cluster from forming or cause constant role flapping, not the specific failover failure described. Active-active also relies on session synchronization and load-balancing algorithms, but this does not address why the passive unit cannot take over.

  • ✗

    The session synchronization is disabled.

    Why it's wrong here

    Disabling session synchronization would allow the cluster to form and failover to occur, but existing TCP/UDP sessions would be dropped when the passive unit becomes active. This is a usability and reliability issue, not a root cause preventing the failover process itself—the passive unit would still transition to active. In the described scenario, the failure is likely due to a fundamental incompatibility between the units, not the lack of session mirroring.

  • ✓

    The passive unit has a different firmware version.

    Why this is correct

    In FortiGate FGCP HA, both members must run the exact same firmware version and build. If the passive unit has a different firmware version, the cluster will fail to synchronize configurations and may not establish a proper HA relationship, causing failover to fail or behave unpredictably. This is a known requirement: firmware mismatch is one of the most common causes of HA cluster formation and failover problems, and it is the correct answer because it directly prevents the passive unit from serving as a valid standby.

  • ✗

    The heartbeat interface is down.

    Why it's wrong here

    A down heartbeat interface would cause the HA cluster to lose inter-unit communication, which is typically detected quickly and may trigger a failover or both units to become active (split-brain). However, this symptom is different from the described failure: if the heartbeat is down, the passive unit might attempt to take over, but the cluster would not be able to verify the active unit's status. In contrast, a firmware mismatch prevents the cluster from ever establishing a proper synchronized state, making it the more likely cause of a failover malfunction.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.