NSE7 Advanced Networking and SD-WAN Practice Question
A FortiGate has an SD-WAN rule with two members: port1 and port2. The rule uses the 'lowest-cost' algorithm. The administrator configures a performance SLA that monitors latency to a remote server. The SLA is applied to both members. After some time, port1's latency exceeds the SLA threshold and its status becomes 'dead'. What happens to new sessions that match the SD-WAN rule?
⚠ Common exam trap
The trap here is assuming that lowest-cost will still choose a dead member if it has the lowest cost, but SLA status takes precedence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
New sessions will be sent to port2, because port1 is excluded due to SLA failure.
When a performance SLA fails, the member is marked as dead and excluded from SD-WAN rule selection. The FortiGate will use the remaining alive member, port2, for new sessions. This behavior ensures that traffic is only sent over links that meet the configured performance criteria. The lowest-cost algorithm only considers alive members, so port1 is not used while it is dead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
New sessions will be dropped until port1's SLA status becomes alive again.
Why it's wrong here
The FortiGate does not drop sessions when a member fails its SLA. It will use the remaining alive members to maintain connectivity. Dropping sessions would cause unnecessary downtime. The SD-WAN rule is designed to provide resilience by failing over to other members when one becomes unavailable.
- ✗
New sessions will be load balanced across both members, but existing sessions on port1 will be re-evaluated.
Why it's wrong here
When a member is dead, it is not used for new sessions. Load balancing across both members would only occur if both were alive. Existing sessions may be affected depending on the configuration, but new sessions will not be sent to a dead member. The FortiGate does not re-evaluate existing sessions by default; they may continue on the dead link or be re-established based on other settings.
- ✓
New sessions will be sent to port2, because port1 is excluded due to SLA failure.
Why this is correct
When a member fails its performance SLA, it is marked as dead and is no longer eligible for selection by the SD-WAN rule. The FortiGate will automatically use the remaining alive member, port2, for new sessions. This ensures that traffic is not sent over a link that does not meet the required performance criteria.
- ✗
New sessions will still be sent to port1 because lowest-cost ignores SLA status.
Why it's wrong here
The lowest-cost algorithm selects the lowest-cost member among those that are alive. If a member fails its SLA and is marked dead, it is excluded from selection regardless of its cost. The FortiGate prioritizes SLA compliance over cost. Therefore, port1 would not be used for new sessions while it is dead.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.