Courseiva
Security Profiles →mediumMatching

NSE4 Security Profiles Practice Question

Match each Fortinet HA mode to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

One unit handles traffic; standby unit takes over on failure

Both units handle traffic simultaneously for load balancing

Multiple units act as a single logical firewall

Ensures active sessions are preserved after failover

FortiGate Clustering Protocol used for HA synchronization

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Active-Passive HA: One FortiGate handles traffic while the other is on standby.

Common FortiGate HA modes: Active-Passive (primary/standby) and Active-Active (both active). Distractors swap the definitions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Active-Passive HA: One FortiGate handles traffic while the other is on standby.

    Why this is correct

    In Fortinet's FortiGate Cluster Protocol, Active-Passive HA designates a single primary unit to actively process all traffic sessions. The backup unit remains in a standby state, maintaining synchronized configuration and session information via the heartbeat interface, and takes over only upon detection of a failure.

  • ✓

    Active-Active HA: Both FortiGates handle traffic simultaneously.

    Why this is correct

    Active-Active HA utilizes FGCP's load-balancing mode so that both FortiGate cluster members concurrently forward data-plane traffic. The cluster distributes new sessions between the units using a hash-based algorithm, while one unit still retains control-plane leadership for management and synchronization.

  • ✗

    Active-Passive HA: Both FortiGates handle traffic simultaneously.

    Why it's wrong here

    This pairing mislabels Active-Passive HA because a passive unit, by definition, does not handle live traffic; it remains idle for redundancy. Two units simultaneously processing traffic is the characteristic behavior of Active-Active HA, not a standby configuration.

  • ✗

    Active-Active HA: One FortiGate handles traffic while the other is on standby.

    Why it's wrong here

    Claiming Active-Active HA has one unit on standby contradicts the model's purpose of concurrent traffic processing. An active-active cluster forwards sessions on both members, so if a unit is waiting in standby, that setup is instead Active-Passive HA.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.