NSE4 High Availability and Diagnostics Practice Question
An administrator needs to configure HA on a pair of FortiGates with the following requirements: the cluster must support session failover for TCP, UDP, and ICMP; the management interface should be accessible on both units; and the failover must be triggered if port2 goes down. Which TWO settings must be configured? (Choose two.)
⚠ Common exam trap
NSE4 often tests the misconception that active-passive mode alone provides session failover, when in fact session pickup must be explicitly enabled and monitored interfaces must be configured to trigger failover.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable session pickup
Option A (Enable session pickup) is correct because session pickup is the FortiGate HA setting that synchronizes session state tables across cluster members, which is exactly what enables TCP, UDP, and ICMP sessions to survive a failover to the other unit. Option C (Add port2 to the monitored interfaces) is correct because HA monitors only the interfaces explicitly listed in the monitored-interface configuration; adding port2 ensures that if that link goes down, the unit's HA priority is reduced or it fails over as required. Option B is not required because the requirement is that the management interface be reachable on both units, which is achieved by allowing management access on the HA interfaces or via reserved management interfaces, not by a mandatory dedicated management interface setting. Option D is not required because session failover and interface monitoring work in both active-passive and active-active modes, so the mode does not have to be active-passive. Option E is not required because override only controls whether a unit with higher priority preempts the primary after it recovers; it is not needed to trigger failover on a link-down event.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable session pickup
Why this is correct
Enabling session pickup is essential for stateful failover in a FortiGate HA cluster. It synchronizes the session table, including NAT translations, TCP/UDP state, and even application-layer protocol states, between the primary and standby units. This ensures that when a failover occurs, existing connections are not dropped and can continue seamlessly on the new primary. Without session pickup, even if the interface goes down and failover is triggered, all active sessions would be lost, causing disruption to users.
- ✗
Configure a dedicated management interface
Why it's wrong here
A dedicated management interface is not a requirement for FortiGate HA operation. The HA management IP can be assigned to any existing interface, including a physical port, a VLAN subinterface, or a dedicated management port if available. FortiGate allows the same interface to be used for both data traffic and management, so creating a separate management interface is only an optional best practice for network segmentation and security. It does not affect session synchronization or interface monitoring capabilities, so it is not the correct configuration step for this scenario.
- ✓
Add port2 to the monitored interfaces
Why this is correct
Adding port2 to the monitored interfaces is a correct HA configuration step because it enables link failover detection. When a monitored interface on the active unit loses its physical link or goes down, the FortiGate HA cluster will treat that unit as failed and trigger a failover to the standby unit. This is crucial for maintaining network redundancy when critical uplinks or downstream links fail. Monitoring interfaces is independent of session pickup and ensures that the HA cluster reacts promptly to link-level failures, not just device-level crashes.
- ✗
Set the HA mode to active-passive
Why it's wrong here
Setting the HA mode to active-passive (A-P) is a valid HA configuration mode where one unit is actively passing traffic and the other is in standby, but this alone does not enable session synchronization or interface monitoring. The HA mode is a basic prerequisite for any HA setup, yet the question is specifically asking about a configuration to ensure session continuity and link failure detection. In A-P mode, you still need to separately configure session pickup and monitored interfaces, so this option is not the direct answer to the stated requirement.
- ✗
Set the HA override to enabled
Why it's wrong here
Enabling HA override controls preemption in the cluster, which determines whether a unit with higher priority can reclaim the primary role after a failover event. This setting is unrelated to session synchronization or interface monitoring; it only affects which unit becomes active when a previously failed unit recovers. Enabling override could cause unnecessary failovers to occur when a unit returns to service, but it does not influence the session table synchronization or the detection of link failures. Therefore, it is not the correct setting for ensuring failover happens due to interface down events or for preserving sessions across failover.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Refer to the exhibit. An administrator has configured HA on two FortiGate units. During a failover test, the secondary unit does not take over when the primary fails. What is the most likely cause?
hard- A.Session pickup is enabled but session-pickup-connectionless is also enabled, causing conflict.
- B.Override is disabled, so the secondary cannot become primary.
- C.The priority on the secondary is set to a higher value than the primary.
- ✓ D.The heartbeat interface (port3) is down on the secondary unit.
Why D: In an HA cluster, the heartbeat interface is critical for communication between primary and secondary units. If the heartbeat interface (port3) is down on the secondary unit, it cannot receive or send HA heartbeat packets, so the secondary will not detect the primary's failure or negotiate a takeover. This directly prevents the secondary from assuming the primary role, making D the correct answer.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.