NSE4 High Availability and Diagnostics Practice Question
An administrator needs to ensure that in an active-passive HA cluster, the primary unit always remains the preferred master unless it fails, regardless of other factors. The administrator sets the primary's HA priority to 200 and the secondary to 100. However, after a reboot of the primary, the secondary becomes the primary. What additional step is required?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set 'set override enable' under config system ha
In HA, the 'override' setting (or 'set override enable') ensures that when the primary recovers, it will preempt the current primary and become active again. Without override, the cluster uses a non-preemptive mode: once a unit becomes primary, it stays primary even if a higher-priority unit comes back online.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set 'set ha-mgmt-status enable' on the primary
Why it's wrong here
Enabling 'ha-mgmt-status' on the primary interface only allows that interface to be used for management traffic (such as HTTPS or SSH) when the unit is in an HA cluster. It does not affect HA failover behavior or the mastership priority. Management access configuration is independent of the preemption logic that controls whether a recovered unit can reclaim its role as primary. Therefore, this command would not cause the cluster to fail back to the primary after a failover.
- ✗
Reduce the secondary priority to 0
Why it's wrong here
Lowering the secondary's priority to 0 makes it the least preferred unit in the cluster, but it does not change the failback behavior. In FortiGate HA, even if the secondary has a lower priority, once it becomes primary (due to a failure of the original primary), it will remain primary unless the 'override' setting is enabled. Without override, the cluster does not automatically preempt to a higher-priority unit simply because that unit recovers. Thus, reducing the secondary's priority by itself does not trigger a switch back to the original primary.
- ✗
Increase the primary priority to 255
Why it's wrong here
Increasing the primary's priority to 255 gives it the highest possible priority, but this only affects which unit is elected as primary during the initial election or when a failover occurs. In the default HA configuration, 'override' is disabled, meaning the cluster will not automatically fail back to a unit that comes online with a higher priority after a failover. The primary may already have a high priority, but without the override flag, the recovered unit will not forcefully take over. Therefore, simply raising the priority to 255 does not enable the desired active-passive failback behavior.
- ✓
Set 'set override enable' under config system ha
Why this is correct
Enabling 'override' in the HA configuration is the correct way to allow a higher-priority unit to preempt and become primary again after it recovers from a failure. When 'override' is enabled, the cluster continuously compares the priority of all units, and if a unit with a higher priority comes back online, it will actively take over the primary role. This ensures that in an active-passive setup, the preferred primary unit will regain mastership after a failover, instead of letting the secondary remain as primary indefinitely. The command is configured under 'config system ha' and is essential for automatic failback.
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A FortiGate cluster in active-passive HA is configured with two heartbeat interfaces. The primary unit fails completely. The secondary unit detects the failure and becomes primary. After the original primary recovers, it remains in passive mode. What is the most likely reason for this behavior?
medium- A.The heartbeat interfaces are not properly configured
- ✓ B.The HA override setting is disabled
- C.The priority of the original primary is lower than the current primary
- D.The HA override setting is enabled
Why B: When override is disabled (the default), the recovered unit will not preempt the current primary. The cluster stays with the current primary until it fails. This is the expected behavior for graceful recovery.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.