Courseiva

NSE7 Advanced Networking and SD-WAN Practice Question

A FortiGate with SD-WAN has two members: MPLS (port1) and Broadband (port2). The performance SLA is configured to monitor latency and packet loss. The administrator notices that after a brief outage on the MPLS link, traffic fails over to Broadband but does not fail back when MPLS recovers. What is the likely cause?

⚠ Common exam trap

Test-takers frequently confuse failback with failover triggers or SLA thresholds, assuming the issue is with detection or cost rather than the explicit failback disable setting in the SD-WAN rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SD-WAN rule for the traffic has 'set failback disable'.

The 'set failback disable' command in the SD-WAN rule prevents traffic from automatically returning to the preferred MPLS link after it recovers. By default, failback is enabled, meaning traffic will revert to the higher-priority member once the performance SLA is satisfied again. When disabled, the FortiGate keeps traffic on the backup link indefinitely, which matches the described behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The SD-WAN rule for the traffic has 'set failback disable'.

    Why this is correct

    The SD-WAN rule's failback setting governs whether traffic returns to a preferred member once it recovers. With failback disabled, the rule keeps sessions on Broadband after the MPLS outage, satisfying the stem's symptom of no automatic return. Re-enabling failback restores MPLS preference when its SLA checks pass again.

  • ✗

    The SLA threshold is set too aggressively, causing the link to be considered down long after recovery.

    Why it's wrong here

    An aggressive threshold would mark the link down sooner, not keep it down after recovery; probes would pass once MPLS latency and loss return to normal. Threshold tuning is tempting because it controls link-state decisions, but it does not prevent failback when the member is healthy.

  • ✗

    The Broadband link has a higher cost, so the FortiGate prefers to keep traffic there.

    Why it's wrong here

    Higher cost affects member preference only when both links are up and within SLA; it does not hold traffic on Broadband after MPLS recovers, since cost is a tiebreaker, not a health override. Cost-based selection is tempting because it steers traffic under normal conditions.

  • ✗

    The SLA probe interval is longer than the outage duration, so the SLA never detected the outage.

    Why it's wrong here

    A longer probe interval would delay detection of the initial outage, yet the stem states failover to Broadband occurred, proving the SLA did detect it. Probe timing is tempting because it governs detection speed, but it cannot explain the absence of failback once MPLS recovers.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.