NSE7 Advanced Networking and SD-WAN Practice Question
A FortiGate is configured with two SD-WAN members (port1 and port2). The administrator sets an SD-WAN rule with 'set load-balance-mode source-dst-ip' for all internal traffic. The source IP is 10.0.0.1 and destination IP is 172.16.0.1. Which factor determines the outgoing interface for this traffic?
⚠ Common exam trap
Test-takers frequently confuse 'source-dst-ip' with 'source-ip' or 'destination-ip' modes, or incorrectly assume that SD-WAN load balancing always considers real-time link utilization, which is only true for 'spillover' or 'lowest-cost' strategies, not hash-based modes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The combination of source IP and destination IP hashed to select an interface
With 'set load-balance-mode source-dst-ip', the FortiGate performs a hash of both the source IP and destination IP to deterministically select an outgoing SD-WAN member. This ensures that all packets belonging to the same source-destination pair are consistently forwarded over the same interface, preserving flow symmetry without relying on per-packet metrics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The destination IP only
Why it's wrong here
Destination-only selection corresponds to the destination-ip mode; source-dst-ip hashes the source and destination pair jointly, so the outgoing member depends on both addresses. Destination-ip would be the correct mode if traffic to a specific server had to follow one path.
- ✓
The combination of source IP and destination IP hashed to select an interface
Why this is correct
Source-dst-ip load balancing hashes the source and destination address pair, so 10.0.0.1 to 172.16.0.1 always maps to the same SD-WAN member, satisfying the stem's requirement to identify the determining factor. Unlike source-ip-only, both addresses feed the hash, pinning this flow to one interface.
- ✗
The source IP only
Why it's wrong here
The source-dst-ip mode hashes both addresses together, so the interface is chosen from the combined pair, not the source alone. Source-only selection describes the source-ip mode, which would be correct if the rule specified that mode instead.
- ✗
The interface with the lowest current utilization
Why it's wrong here
Source-dst-ip load balancing hashes the source and destination address pair to select a member, so the same flow always maps to one interface; utilisation plays no part. Lowest-utilisation selection belongs to spillover or volume-based modes, which distribute load dynamically rather than by fixed flow hash.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.