NSE4 High Availability and Diagnostics Practice Question
A FortiGate is configured with an active-passive HA cluster. The admin notices that when the primary unit fails, the secondary takes over, but after the primary recovers, it does not automatically become active again. What is the most likely reason?
⚠ Common exam trap
NSE4 often tests the misconception that the original primary automatically reclaims the active role after recovery — candidates must remember that without override enabled, the current primary retains the role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Override is not enabled
In FortiGate HA, when the primary unit recovers after a failover, it does not automatically reclaim the primary role unless 'override' is enabled. Without override, the current primary (formerly secondary) retains the active role, and the recovered unit becomes the secondary. Enabling override allows the unit with the higher priority (or lower monitor priority value) to take over as primary when it comes back online.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The primary has a lower priority than the secondary
Why it's wrong here
In FortiGate HA, the election of the primary unit is primarily based on priority and then uptime. If the current primary had a lower priority than the secondary, it would not have become the initial primary, and during failback the higher-priority unit would naturally take over. The scenario describes a unit that is already primary but fails to yield on recovery, so lower priority cannot explain the lack of preemption. The issue is not relative priority but the override mechanism that allows a higher-priority backup to force failback.
- ✓
Override is not enabled
Why this is correct
When override is enabled in FortiGate HA, a device with higher priority can preempt the current primary when it comes back online after a failover. Without override, the cluster maintains the current primary even if a higher-priority unit is available, so the original primary remains active after recovery. This is exactly the observed behavior: the higher-priority unit is primary initially, fails over, and on recovery does not reclaim primary because override is off. The priority is used for initial election and for override-based decisions, but failback requires override enabled.
- ✗
Session pickup is disabled
Why it's wrong here
Session pickup (or session failover) controls whether existing sessions are synchronized to the standby unit so they can survive a failover. Disabling it means that sessions are not learned by the backup, so after a failover those sessions are lost. It has no influence on which unit is elected or whether a unit preempts after recovery; that is purely a function of HA priority, uptime, and the override setting. Thus, session pickup being disabled would not cause a higher-priority primary to remain secondary after recovery.
- ✗
The heartbeat interface is down
Why it's wrong here
The heartbeat (or HA) interface is used for monitoring the peer unit's status and synchronizing state. If the heartbeat interface goes down, the cluster may detect a failure and potentially trigger a failover or, if both units think they are alone, cause a split-brain condition. But the described behavior—where a specific unit fails to reclaim primary after recovery—indicates the cluster is otherwise healthy and able to communicate. A down heartbeat interface would disrupt the cluster and lead to unpredictable behavior, not a clean failback that is simply blocked by the lack of override.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A FortiGate administrator has configured an active-passive HA cluster. After a failover event, the former primary unit comes back online and immediately takes over as primary again, causing another failover. The administrator wants the original primary to stay in standby until the current primary fails. Which setting should be configured?
hard- A.Enable HA override on both units
- B.Set the HA mode to active-active
- ✓ C.Disable HA override on both units
- D.Increase the HA priority on the primary unit
Why C: HA override (set ha-override enable) causes a device to resume primary role when it becomes available with higher priority. Disabling override prevents this preemptive behavior.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.