NSE4 High Availability and Diagnostics Practice Question
A FortiGate is configured in an A-P HA cluster. The administrator wants to ensure that session failover occurs for UDP-based voice traffic. Which TWO settings must be enabled?
⚠ Common exam trap
Watch out — candidates often confuse configuration synchronization (which replicates config files) with session synchronization (which replicates dynamic session state), leading them to incorrectly select Option C instead of A.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable UDP session synchronization.
UDP session synchronization must be enabled to replicate UDP session state between HA cluster members, ensuring that active sessions for voice traffic (which typically uses UDP) are seamlessly taken over by the standby unit during a failover. Without this setting, UDP sessions are not synchronized by default, and voice calls would drop.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable UDP session synchronization.
Why this is correct
Enabling UDP session synchronization directly instructs the FGCP cluster to replicate UDP session table entries from the primary unit to the standby. Because UDP is connectionless, the standby cannot infer active flows from handshake packets, so without this explicit setting, return traffic for existing UDP conversations will be dropped after failover. This setting is protocol-specific and works alongside session pickup to ensure NAT bindings and idle timers are preserved on the new primary.
- ✗
Set HA override to enabled.
Why it's wrong here
HA override is a preemption control that determines whether a previously failed primary unit can reclaim its role by forcing the current primary to relinquish it. This setting affects role selection during failover and recovery, but it has no impact on what session state is copied between cluster members. Enabling override could even trigger unnecessary switchovers, but it will not cause UDP session tables to be populated on the standby.
- ✗
Enable configuration synchronization.
Why it's wrong here
Configuration synchronization copies the FortiGate's policy, object, and system settings from the primary to the standby so that both units enforce identical rules. This is an automatic FGCP function, but it operates at the static configuration layer, not on the dynamic session table. Even with perfectly synchronized configurations, the standby unit still has no knowledge of existing UDP flows unless session synchronization and session pickup are explicitly enabled.
- ✓
Enable session pickup.
Why this is correct
Session pickup is the umbrella HA mechanism that transfers active session information from the primary to the standby unit, allowing the standby to accept and forward traffic without interruption after failover. For UDP, this functionality is essential because the standby must know the session keys, NAT translations, and timeouts that were created by the original primary. Enabling session pickup is a prerequisite for protocol-specific synchronization such as UDP session synchronization, and together they provide seamless failover for connectionless traffic.
- ✗
Set failover hold time to 1 second.
Why it's wrong here
Failover hold time is the delay before a standby unit assumes the primary role after detecting a failure in the active unit. Lowering it to 1 second makes failover happen more quickly, but it does not affect whether any session data is synchronized prior to the failure. The standby's session table remains empty or stale if UDP session synchronization is disabled, so a fast failover still results in dropped UDP flows and broken application connections.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.