NSE4 High Availability and Diagnostics Practice Question
An administrator configures HA override on a cluster with priority 200 on primary and 100 on secondary. The primary fails, secondary takes over. When primary recovers, what happens?
⚠ Common exam trap
NSE4 often tests the difference between HA override enabled vs disabled, and candidates may confuse override with manual failback or assume both units become active.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Primary immediately takes over as active
With HA override enabled, the primary unit with higher priority (200) will preempt the secondary (100) once it recovers and rejoins the cluster. The primary immediately takes over as active because override allows a higher-priority unit to force a failback. This is the intended behavior of override in FortiGate HA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Both units become active, causing a conflict
Why it's wrong here
In a FortiGate HA cluster, the architecture is specifically designed to prevent split-brain: the backup unit continuously monitors the primary's heartbeat and does not forward traffic while in standby. Enabling override does not change this fundamental design; it only affects which unit takes over after a failure and recovery. The HA state and link failover mechanisms enforce a single active unit at any time, even during preemption, so both units never become active simultaneously.
- ✗
Secondary remains active until next failover
Why it's wrong here
Override is explicitly designed to cause immediate preemption: when a higher-priority unit—typically the configured primary—recovers and rejoins the cluster, it instantly claims the active role. The secondary does not remain active until the next natural failover, because override overrides the stickiness that might otherwise keep the current active unit in place. This immediate re-election is automatic and does not wait for another failure or for a scheduled failover event.
- ✗
The administrator must manually trigger failback
Why it's wrong here
With HA override enabled, failback is fully automated: as soon as the primary unit is healthy and its heartbeat is restored, it will preempt the secondary and become active again. No administrator action is needed to trigger failback, as the cluster's preemption logic handles the transition automatically. This is a clear contrast to non-preemptive mode, where manual intervention or a separate failover event is often required to return the active role to the primary.
- ✓
Primary immediately takes over as active
Why this is correct
When override is enabled on the cluster, a recovered primary unit with a higher priority will immediately take over as active, preempting the current secondary. The takeover occurs after the cluster re-establishes heartbeat and synchronizes session state, ensuring that traffic convergence is orderly. This preemptive behavior is the defining feature of HA override, and it distinguishes the mode from non-preemptive operation where the current active unit would otherwise remain active.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator is configuring a FortiGate HA cluster and wants to ensure that the primary unit is always preferred based on its configuration priority. Which setting should be enabled to allow the primary unit to resume its role after a failover if it regains connectivity?
medium- A.set ha-inherit-priority enable
- ✓ B.set override enable
- C.set session-pickup enable
- D.set ha-priority 255
Why B: The 'set override enable' setting allows the primary unit to resume its role after a failover if it regains connectivity, based on its configured priority. Without override, the cluster does not preempt; the current primary remains primary even if a higher-priority unit rejoins. Enabling override ensures the primary unit always takes back its role when available.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.