Courseiva

NSE7 Advanced Networking and SD-WAN Practice Question

A FortiGate with SD-WAN enabled uses two members: MPLS (10 ms latency) and Internet (40 ms latency). The SD-WAN rule uses 'Best Quality' strategy with latency as the metric. Traffic to a critical application (10.1.1.0/24) is currently using the MPLS link. The MPLS link's latency increases to 60 ms due to a routing issue. How will FortiGate handle new sessions to 10.1.1.0/24?

⚠ Common exam trap

Watch out — candidates often assume SD-WAN automatically re-routes all traffic (including existing sessions) when link quality degrades, but in reality, only new sessions are affected unless a session-based failover mechanism like session TTL or manual intervention is configured.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

New sessions will use the Internet link; existing sessions continue on MPLS.

The 'Best Quality' strategy with latency metric selects the link with the lowest latency for new sessions. When MPLS latency rises to 60 ms, it exceeds the Internet link's 40 ms, so new sessions will be steered to the Internet. However, SD-WAN does not preemptively rehash existing sessions; they remain on the original link (MPLS) until they expire or are torn down.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    New sessions will use the Internet link; existing sessions continue on MPLS.

    Why this is correct

    Best Quality evaluates link metrics per new session, so once MPLS latency exceeds the Internet member's 40 ms, new sessions to 10.1.1.0/24 select the Internet link. FortiGate does not rebalance established sessions, so existing MPLS flows persist until they end.

  • ✗

    FortiGate will wait for the MPLS link to recover before sending new traffic.

    Why it's wrong here

    Best Quality recalculates per new session, so FortiGate re-evaluates link metrics rather than holding traffic for MPLS recovery. Waiting describes fail-wait or link-recovery behaviour, which applies when a member is administratively down or a priority rule pins traffic, not when latency simply degrades on a healthy link.

  • ✗

    All sessions immediately switch to the Internet link.

    Why it's wrong here

    Best Quality switches only new sessions; established sessions to 10.1.1.0/24 remain on MPLS unless the rule enables session re-evaluation or the link fails. Immediate switching of all sessions describes a rule with session-pickup or failover on link-down, not latency-based Best Quality selection.

  • ✗

    Existing sessions continue on MPLS; new sessions will use MPLS until the next SLA probe.

    Why it's wrong here

    Best Quality re-evaluates link selection on each new session using current SLA probe results, so new sessions move to the Internet link once MPLS latency exceeds the threshold. Waiting for the next probe delays that decision. It is tempting because probe intervals do govern measurement freshness, which suits static SD-WAN rules.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.