NSE7 Advanced Networking and SD-WAN Practice Question
A FortiGate is configured with two SD-WAN members: port1 and port2, both with the same cost. An SD-WAN rule is set to use the 'lowest-cost (SLA)' strategy. The administrator observes that all traffic is going out port1, even though port2 is also within SLA. What is the most likely reason?
⚠ Common exam trap
The trap here is assuming that equal cost and SLA compliance automatically result in load balancing, ignoring the operational state of the interface or its routing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Port2 is administratively down or has no active route, so it is excluded from the SD-WAN rule.
In lowest-cost (SLA), traffic is distributed among members with the lowest cost that meet SLA. If port2 is down or has no route, it is removed from consideration, leaving port1 as the only viable member. Equal costs alone do not guarantee load sharing; operational status and routing must be valid.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Port2 is configured with a higher link priority value, causing it to be preferred over port1.
Why it's wrong here
Link priority is used in some strategies to prefer one member over another, but in lowest-cost (SLA), cost is the primary metric. If priorities differ, they can influence selection, but the scenario states both members have the same cost and are within SLA. A higher priority on port2 would actually make it more preferred, not less, so this does not explain why port1 is used exclusively.
- ✗
The 'lowest-cost (SLA)' strategy always selects the first member in the list when costs are equal.
Why it's wrong here
The lowest-cost (SLA) strategy does not simply select the first member when costs are equal. It uses a round-robin or weighted distribution among members with the same lowest cost, unless other factors like link priority or SLA status affect selection. This option misrepresents the algorithm's behavior.
- ✓
Port2 is administratively down or has no active route, so it is excluded from the SD-WAN rule.
Why this is correct
If port2 is administratively down or lacks a valid route, it cannot be used for traffic, even if it is within SLA. The FortiGate would then use only port1. This is a common reason for traffic to be sent exclusively over one member despite equal costs and SLA status.
- ✗
The SD-WAN rule is configured with 'set gateway enable', which forces traffic through the first member.
Why it's wrong here
The 'set gateway enable' command is used to enable gateway health-check for the rule, not to force traffic through a specific member. It does not override the load-balancing strategy. This option describes an incorrect function of that setting, so it is not the cause of the traffic pattern.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.