Courseiva

NSE4 High Availability and Diagnostics Practice Question

An administrator configures HA override on a cluster with priority 200 on primary and 100 on secondary. The primary fails, secondary takes over. When primary recovers, what happens?

⚠ Common exam trap

NSE4 often tests the difference between HA override enabled vs disabled, and candidates may confuse override with manual failback or assume both units become active.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Primary immediately takes over as active

With HA override enabled, the primary unit with higher priority (200) will preempt the secondary (100) once it recovers and rejoins the cluster. The primary immediately takes over as active because override allows a higher-priority unit to force a failback. This is the intended behavior of override in FortiGate HA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Both units become active, causing a conflict

    Why it's wrong here

    In a FortiGate HA cluster, the architecture is specifically designed to prevent split-brain: the backup unit continuously monitors the primary's heartbeat and does not forward traffic while in standby. Enabling override does not change this fundamental design; it only affects which unit takes over after a failure and recovery. The HA state and link failover mechanisms enforce a single active unit at any time, even during preemption, so both units never become active simultaneously.

  • ✗

    Secondary remains active until next failover

    Why it's wrong here

    Override is explicitly designed to cause immediate preemption: when a higher-priority unit—typically the configured primary—recovers and rejoins the cluster, it instantly claims the active role. The secondary does not remain active until the next natural failover, because override overrides the stickiness that might otherwise keep the current active unit in place. This immediate re-election is automatic and does not wait for another failure or for a scheduled failover event.

  • ✗

    The administrator must manually trigger failback

    Why it's wrong here

    With HA override enabled, failback is fully automated: as soon as the primary unit is healthy and its heartbeat is restored, it will preempt the secondary and become active again. No administrator action is needed to trigger failback, as the cluster's preemption logic handles the transition automatically. This is a clear contrast to non-preemptive mode, where manual intervention or a separate failover event is often required to return the active role to the primary.

  • ✓

    Primary immediately takes over as active

    Why this is correct

    When override is enabled on the cluster, a recovered primary unit with a higher priority will immediately take over as active, preempting the current secondary. The takeover occurs after the cluster re-establishes heartbeat and synchronizes session state, ensuring that traffic convergence is orderly. This preemptive behavior is the defining feature of HA override, and it distinguishes the mode from non-preemptive operation where the current active unit would otherwise remain active.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator is configuring a FortiGate HA cluster and wants to ensure that the primary unit is always preferred based on its configuration priority. Which setting should be enabled to allow the primary unit to resume its role after a failover if it regains connectivity?

medium
  • A.set ha-inherit-priority enable
  • ✓ B.set override enable
  • C.set session-pickup enable
  • D.set ha-priority 255

Why B: The 'set override enable' setting allows the primary unit to resume its role after a failover if it regains connectivity, based on its configured priority. Without override, the cluster does not preempt; the current primary remains primary even if a higher-priority unit rejoins. Enabling override ensures the primary unit always takes back its role when available.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.