Courseiva

Key Characteristics of FortiGate Active-Passive HA

An administrator is configuring a FortiGate HA cluster in active-passive mode with two units. Which two conditions must be met for failover to occur? (Choose two.)

⚠ Common exam trap

The trap is that candidates may think there are three valid failover conditions, but only two are standard. Often, they mistakenly include CPU threshold or session sync loss as triggers, but FortiGate HA does not use resource utilization or session sync status to initiate failover unless custom configurations are applied.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A monitored interface on the primary unit goes down

Option A is correct because in an active-passive FortiGate HA cluster, failover is triggered when a monitored interface (configured under config system ha with monitor-interface) goes down on the primary unit, causing the cluster to renegotiate and the secondary to take over. Option B is correct because loss of all heartbeat communication (via the HA heartbeat interfaces, using FGCP over UDP/703 or Ethernet frames) causes the secondary to conclude the primary has failed and assume the primary role. Option C is not correct because priority is only evaluated at cluster formation or when a unit rejoins; a higher priority on the secondary does not by itself force a failover of an established cluster. Option D is not correct because CPU usage thresholds are not a native HA failover trigger in FortiOS. Option E is not correct because session synchronization packets are not heartbeats; stopping session sync alone does not trigger failover, only loss of heartbeat or a monitored interface failure does.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A monitored interface on the primary unit goes down

    Why this is correct

    A monitored interface failing triggers failover because FortiGate HA actively tracks link health; when a monitored interface on the primary goes down, the cluster treats it as a failure condition and promotes the secondary. This satisfies the stem's requirement for a valid failover trigger in active-passive mode.

  • ✓

    The primary unit loses all heartbeat communication with the secondary unit

    Why this is correct

    Loss of all heartbeat communication triggers failover because the secondary unit stops receiving HA hello packets on the heartbeat interfaces and, after the configured failover threshold, assumes the primary role. This satisfies the stem's requirement that the primary unit becomes unreachable, since silent heartbeat interfaces are indistinguishable from a failed primary.

  • ✗

    The secondary unit receives a higher priority configuration

    Why it's wrong here

    Failover in active-passive HA is triggered by monitored interface link failure or by the primary unit becoming unresponsive via heartbeat; a secondary unit cannot seize the primary role merely by holding a different priority value. Priority only determines which unit becomes primary at cluster formation or after a reboot, not during runtime failover.

  • ✗

    The primary unit's CPU usage exceeds 90%

    Why it's wrong here

    CPU exhaustion on the primary does not trigger HA failover; FortiGate HA monitors interface link state and heartbeat (hello) packets, not processor load. It is tempting because resource thresholds appear in some other high-availability products, but FortiGate requires link failure or heartbeat loss, with CPU-based failover only available through optional remote link monitoring of upstream targets.

  • ✗

    The primary unit stops sending session synchronization packets

    Why it's wrong here

    Session synchronisation packets carry connection state between cluster members so sessions survive failover; they are not the HA heartbeat. Failover occurs when heartbeat hello packets stop arriving on monitored interfaces, not when session sync traffic ceases. It is tempting because both are inter-unit traffic, but only heartbeat loss triggers role transition.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.