NSE7 Advanced Networking and SD-WAN Practice Question
A network admin needs to configure a FortiGate to load balance traffic across two ISP links using SD-WAN. The requirement is to use both links simultaneously for different sessions based on source-destination IP hash. Which two settings are required? (Select TWO.)
⚠ Common exam trap
Watch out — candidates often confuse 'load balancing algorithm' (like source-dest-ip-hash) with 'strategy' (like best quality) or assume that performance SLAs are mandatory for any SD-WAN rule, when in fact SLAs are only needed for dynamic path selection based on link quality.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an SD-WAN zone with both WAN members
Option A is correct because SD-WAN load balancing requires the WAN interfaces to be grouped into an SD-WAN zone, which serves as the logical interface containing both ISP members that traffic can be distributed across. Option B is correct because the requirement explicitly states sessions must be distributed based on a source-destination IP hash, and the SD-WAN rule's load-balance algorithm must be set to 'source-dest-ip-hash' to achieve per-session hashing across both links simultaneously. Option C is not required because a performance SLA is only needed for quality-based or SLA-driven steering, not for pure hash-based load balancing. Option D is incorrect because the 'best quality' strategy selects a single best link based on SLA metrics rather than distributing sessions across both links. Option E is incorrect because spillover is a strategy used to send traffic to a secondary link only when the primary exceeds a threshold, which does not satisfy the requirement of using both links simultaneously for different sessions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an SD-WAN zone with both WAN members
Why this is correct
An SD-WAN zone groups the two WAN interfaces as members, which is the prerequisite for any SD-WAN rule to reference them. Without the zone, the load-balancing rule cannot bind both ISP links, so this satisfies the requirement to use both links simultaneously.
- ✓
Configure an SD-WAN rule with load balancing algorithm 'source-dest-ip-hash'
Why this is correct
The source-dest-ip-hash algorithm hashes each session's source and destination IP pair, distributing different sessions across both WAN members concurrently. This directly satisfies the requirement to load balance using both links simultaneously based on source-destination IP hash.
- ✗
Add a performance SLA for each member
Why it's wrong here
A performance SLA measures latency, jitter and packet loss to drive health-based failover; it does not implement source-destination IP hashing. It is tempting because SD-WAN commonly uses SLAs to steer traffic by link quality, which would be correct for quality-based load balancing rather than the hash-based distribution required here.
- ✗
Set the rule strategy to 'best quality'
Why it's wrong here
'Best quality' selects a single member per session according to SLA metrics, so both links are not used simultaneously by hash. It is tempting because it is a valid SD-WAN rule strategy, and would be correct when the requirement is to steer traffic onto the healthiest link rather than distribute sessions across both.
- ✗
Enable 'spillover' under the SD-WAN rule
Why it's wrong here
Spillover forwards traffic to a second member once a link exceeds a bandwidth threshold, so sessions still follow link capacity rather than a source-destination hash. It is tempting because it uses both links, and it would be correct when balancing by measured utilisation instead of per-session hashing.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.