Courseiva

NSE7 Advanced Networking and SD-WAN Practice Question

A FortiGate is configured with two SD-WAN members (port1 and port2). The administrator sets an SD-WAN rule with 'set load-balance-mode source-dst-ip' for all internal traffic. The source IP is 10.0.0.1 and destination IP is 172.16.0.1. Which factor determines the outgoing interface for this traffic?

⚠ Common exam trap

Test-takers frequently confuse 'source-dst-ip' with 'source-ip' or 'destination-ip' modes, or incorrectly assume that SD-WAN load balancing always considers real-time link utilization, which is only true for 'spillover' or 'lowest-cost' strategies, not hash-based modes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The combination of source IP and destination IP hashed to select an interface

With 'set load-balance-mode source-dst-ip', the FortiGate performs a hash of both the source IP and destination IP to deterministically select an outgoing SD-WAN member. This ensures that all packets belonging to the same source-destination pair are consistently forwarded over the same interface, preserving flow symmetry without relying on per-packet metrics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The destination IP only

    Why it's wrong here

    Destination-only selection corresponds to the destination-ip mode; source-dst-ip hashes the source and destination pair jointly, so the outgoing member depends on both addresses. Destination-ip would be the correct mode if traffic to a specific server had to follow one path.

  • ✓

    The combination of source IP and destination IP hashed to select an interface

    Why this is correct

    Source-dst-ip load balancing hashes the source and destination address pair, so 10.0.0.1 to 172.16.0.1 always maps to the same SD-WAN member, satisfying the stem's requirement to identify the determining factor. Unlike source-ip-only, both addresses feed the hash, pinning this flow to one interface.

  • ✗

    The source IP only

    Why it's wrong here

    The source-dst-ip mode hashes both addresses together, so the interface is chosen from the combined pair, not the source alone. Source-only selection describes the source-ip mode, which would be correct if the rule specified that mode instead.

  • ✗

    The interface with the lowest current utilization

    Why it's wrong here

    Source-dst-ip load balancing hashes the source and destination address pair to select a member, so the same flow always maps to one interface; utilisation plays no part. Lowest-utilisation selection belongs to spillover or volume-based modes, which distribute load dynamically rather than by fixed flow hash.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.