Courseiva

NSE4 System and Network Administration Practice Question

Exhibit

Refer to the exhibit.
config router static
    edit 1
        set device port1
        set gateway 203.0.113.1
        set dst 0.0.0.0 0.0.0.0
        set distance 10
    next
    edit 2
        set device port2
        set gateway 10.0.0.1
        set dst 0.0.0.0 0.0.0.0
        set distance 20
    next
end

Refer to the exhibit. The FortiGate has two default routes. The administrator attempts to ping 8.8.8.8 from the CLI and receives no response. What is the most likely reason?

⚠ Common exam trap

A common mix-up: candidates assume both default routes are active and load-balanced, but FortiGate uses administrative distance to select a single active route, and if the gateway of that route is unreachable, the route becomes invalid and no traffic is forwarded until the next route is considered.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The gateway 203.0.113.1 (port1) is unreachable

When a FortiGate has multiple default routes, it uses the route with the lowest distance (administrative distance) as the primary route. If the gateway for the primary route (203.0.113.1 on port1) is unreachable, the FortiGate will not be able to reach 8.8.8.8, even if a secondary default route exists. The ping fails because the device cannot ARP for the gateway or the next-hop is down, causing the route to be inactive.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The second route is overwriting the first route

    Why it's wrong here

    FortiGate does not replace a lower-distance route with a higher-distance route when the destination prefix is identical. The routing table (RIB) can hold multiple static routes to 0.0.0.0/0 as long as their administrative distances differ, and the router selects the one with the lowest distance as the active route. The distance-20 route remains in the RIB as a backup candidate, so it is not overwriting or deleting the distance-10 route.

  • ✗

    Both routes are equal-cost and load-balancing is not working

    Why it's wrong here

    Equal-cost multipath (ECMP) load balancing requires routes to have the same administrative distance and same metric (cost) to the same destination. Here the distances are 10 and 20, so the routes are not equal-cost; only the distance-10 route is installed as the preferred route, and the distance-20 route is a floating static backup. Therefore, failing to see load balancing is not a misconfiguration—it is expected behavior when distances differ.

  • ✗

    The configuration is invalid because duplicate default routes are not allowed

    Why it's wrong here

    FortiGate explicitly allows multiple default routes (0.0.0.0/0) in the configuration, provided they are distinguishable by metrics or administrative distances. Having two default static routes with distances 10 and 20 is a valid design for link redundancy, and the configuration will be accepted by the CLI or GUI. Duplicate default routes are only invalid if they have the exact same distance and metric and the platform does not support ECMP, but FortiGate does support it; thus, this is not the reason traffic is failing.

  • ✓

    The gateway 203.0.113.1 (port1) is unreachable

    Why this is correct

    The route via 203.0.113.1 on port1 has an administrative distance of 10, making it the preferred route for all traffic. If that next-hop gateway becomes unreachable—for instance, port1 goes down, the connected network fails, or ARP resolution for 203.0.113.1 fails—the active route is removed or becomes unusable. FortiGate will not immediately fail over to the distance-20 route unless the primary route is completely removed; in many scenarios, traffic is dropped because the lower-distance route is still considered valid in the RIB but cannot forward packets. Thus, unreachability of the primary gateway directly explains the total loss of connectivity.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.