NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator is configuring an ADVPN with a hub-and-spoke topology. The administrator wants to ensure that spoke-to-spoke traffic can be dynamically established without traversing the hub for every packet. The administrator also wants to ensure that the shortcut tunnels are only established when necessary and are torn down when no longer used. Which two statements about ADVPN shortcut tunnels on FortiGate are correct? (Choose two.)
⚠ Common exam trap
The trap here is assuming that ADVPN shortcuts are permanent full-mesh tunnels or that the hub is eliminated, when they are actually on-demand and time-limited.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shortcut tunnels are established when a spoke receives a shortcut offer from the hub and the spoke has a route to the destination spoke's public IP.
ADVPN shortcut tunnels are established on demand when the hub sends a shortcut offer and the originating spoke can reach the destination spoke's public IP. They are torn down after an idle timeout when no traffic matches, reverting traffic to the hub path. This dynamic creation and teardown optimizes spoke-to-spoke communication while preserving the hub as a fallback and control point.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Shortcut tunnels are always established between all spokes at initial VPN bring-up, regardless of traffic patterns.
Why it's wrong here
ADVPN shortcut tunnels are established on demand, not at initial bring-up. The hub and spokes first form a hub-and-spoke topology. Shortcut tunnels are only created when the hub detects traffic that could benefit from a direct path and sends a shortcut offer. Establishing all possible spoke-to-spoke tunnels at bring-up would not scale and would waste resources, which is contrary to the ADVPN design.
- ✗
Shortcut tunnels can only be established between spokes that are in the same IP subnet.
Why it's wrong here
ADVPN shortcut tunnels can be established between spokes regardless of their IP subnets. The spokes typically use different protected subnets, and the shortcut tunnel carries traffic between those subnets. The requirement is that the spokes can reach each other's public IP addresses and that routing and firewall policies permit the traffic. Subnet sameness is not a requirement for shortcut establishment.
- ✓
Shortcut tunnels are established when a spoke receives a shortcut offer from the hub and the spoke has a route to the destination spoke's public IP.
Why this is correct
In ADVPN, the hub sends a shortcut offer to the originating spoke when it detects traffic destined for another spoke. The originating spoke then attempts to establish a direct tunnel to the destination spoke. For this to succeed, the spoke must have a route to the destination spoke's public IP address, which is typically learned via the hub or through the underlay network. This allows spoke-to-spoke traffic to bypass the hub.
- ✓
Shortcut tunnels are torn down after a configured idle timeout when no traffic matches the shortcut, and traffic reverts to the hub path.
Why this is correct
ADVPN shortcut tunnels have an idle timeout. When no traffic matches the shortcut for the configured period, the tunnel is torn down to conserve resources. Subsequent traffic between the spokes will again flow through the hub, and a new shortcut may be negotiated if needed. This dynamic behavior ensures that shortcuts are only maintained when actively used, optimizing resource usage.
- ✗
Shortcut tunnels require the hub to be removed from the routing path permanently once established.
Why it's wrong here
The hub remains part of the topology even after shortcut tunnels are established. The hub is still used for control plane functions, such as sending shortcut offers and maintaining the hub-and-spoke overlay. If a shortcut is torn down, traffic reverts to the hub path. The hub is not permanently removed from the routing path; it continues to serve as a fallback and for management.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.