Courseiva

NSE7 Advanced Networking and SD-WAN Practice Question

A FortiGate is configured with two SD-WAN members: port1 and port2, both with the same cost. An SD-WAN rule is set to use the 'lowest-cost (SLA)' strategy. The administrator observes that all traffic is going out port1, even though port2 is also within SLA. What is the most likely reason?

⚠ Common exam trap

The trap here is assuming that equal cost and SLA compliance automatically result in load balancing, ignoring the operational state of the interface or its routing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Port2 is administratively down or has no active route, so it is excluded from the SD-WAN rule.

In lowest-cost (SLA), traffic is distributed among members with the lowest cost that meet SLA. If port2 is down or has no route, it is removed from consideration, leaving port1 as the only viable member. Equal costs alone do not guarantee load sharing; operational status and routing must be valid.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Port2 is configured with a higher link priority value, causing it to be preferred over port1.

    Why it's wrong here

    Link priority is used in some strategies to prefer one member over another, but in lowest-cost (SLA), cost is the primary metric. If priorities differ, they can influence selection, but the scenario states both members have the same cost and are within SLA. A higher priority on port2 would actually make it more preferred, not less, so this does not explain why port1 is used exclusively.

  • ✗

    The 'lowest-cost (SLA)' strategy always selects the first member in the list when costs are equal.

    Why it's wrong here

    The lowest-cost (SLA) strategy does not simply select the first member when costs are equal. It uses a round-robin or weighted distribution among members with the same lowest cost, unless other factors like link priority or SLA status affect selection. This option misrepresents the algorithm's behavior.

  • ✓

    Port2 is administratively down or has no active route, so it is excluded from the SD-WAN rule.

    Why this is correct

    If port2 is administratively down or lacks a valid route, it cannot be used for traffic, even if it is within SLA. The FortiGate would then use only port1. This is a common reason for traffic to be sent exclusively over one member despite equal costs and SLA status.

  • ✗

    The SD-WAN rule is configured with 'set gateway enable', which forces traffic through the first member.

    Why it's wrong here

    The 'set gateway enable' command is used to enable gateway health-check for the rule, not to force traffic through a specific member. It does not override the load-balancing strategy. This option describes an incorrect function of that setting, so it is not the cause of the traffic pattern.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.