Courseiva

NSE7 Advanced Networking and SD-WAN Practice Question

A network admin needs to configure a FortiGate to load balance traffic across two ISP links using SD-WAN. The requirement is to use both links simultaneously for different sessions based on source-destination IP hash. Which two settings are required? (Select TWO.)

⚠ Common exam trap

Watch out — candidates often confuse 'load balancing algorithm' (like source-dest-ip-hash) with 'strategy' (like best quality) or assume that performance SLAs are mandatory for any SD-WAN rule, when in fact SLAs are only needed for dynamic path selection based on link quality.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an SD-WAN zone with both WAN members

Option A is correct because SD-WAN load balancing requires the WAN interfaces to be grouped into an SD-WAN zone, which serves as the logical interface containing both ISP members that traffic can be distributed across. Option B is correct because the requirement explicitly states sessions must be distributed based on a source-destination IP hash, and the SD-WAN rule's load-balance algorithm must be set to 'source-dest-ip-hash' to achieve per-session hashing across both links simultaneously. Option C is not required because a performance SLA is only needed for quality-based or SLA-driven steering, not for pure hash-based load balancing. Option D is incorrect because the 'best quality' strategy selects a single best link based on SLA metrics rather than distributing sessions across both links. Option E is incorrect because spillover is a strategy used to send traffic to a secondary link only when the primary exceeds a threshold, which does not satisfy the requirement of using both links simultaneously for different sessions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an SD-WAN zone with both WAN members

    Why this is correct

    An SD-WAN zone groups the two WAN interfaces as members, which is the prerequisite for any SD-WAN rule to reference them. Without the zone, the load-balancing rule cannot bind both ISP links, so this satisfies the requirement to use both links simultaneously.

  • ✓

    Configure an SD-WAN rule with load balancing algorithm 'source-dest-ip-hash'

    Why this is correct

    The source-dest-ip-hash algorithm hashes each session's source and destination IP pair, distributing different sessions across both WAN members concurrently. This directly satisfies the requirement to load balance using both links simultaneously based on source-destination IP hash.

  • ✗

    Add a performance SLA for each member

    Why it's wrong here

    A performance SLA measures latency, jitter and packet loss to drive health-based failover; it does not implement source-destination IP hashing. It is tempting because SD-WAN commonly uses SLAs to steer traffic by link quality, which would be correct for quality-based load balancing rather than the hash-based distribution required here.

  • ✗

    Set the rule strategy to 'best quality'

    Why it's wrong here

    'Best quality' selects a single member per session according to SLA metrics, so both links are not used simultaneously by hash. It is tempting because it is a valid SD-WAN rule strategy, and would be correct when the requirement is to steer traffic onto the healthiest link rather than distribute sessions across both.

  • ✗

    Enable 'spillover' under the SD-WAN rule

    Why it's wrong here

    Spillover forwards traffic to a second member once a link exceeds a bandwidth threshold, so sessions still follow link capacity rather than a source-destination hash. It is tempting because it uses both links, and it would be correct when balancing by measured utilisation instead of per-session hashing.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.