Courseiva

NSE7 Advanced Networking and SD-WAN Practice Question

A network administrator configures an SD-WAN zone with two members (port1 and port2) and sets the load balancing algorithm to 'spillover'. The spillover threshold is set to 100 Mbps on port1. If traffic reaches 120 Mbps on port1, what happens to new sessions?

⚠ Common exam trap

Watch out — candidates often confuse spillover with load balancing algorithms like 'lowest latency' or 'round-robin', incorrectly assuming that traffic is dropped, queued, or evenly distributed when the threshold is exceeded, rather than understanding that spillover is a failover-like mechanism that shifts new sessions to the next available member.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

New sessions are sent to port2 until port1 drops below the threshold

When the spillover algorithm is configured with a threshold of 100 Mbps on port1 and traffic reaches 120 Mbps, port1 is considered saturated. The SD-WAN zone then directs all new sessions to port2 until the traffic on port1 drops below the threshold. This is the defined behavior of spillover load balancing in Fortinet SD-WAN, where traffic is shifted away from an overloaded member to maintain performance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All traffic is dropped because the threshold exceeded

    Why it's wrong here

    Spillover diverts only new sessions exceeding the threshold to port2; it never drops traffic. Dropping describes a link-monitor failure or a hard bandwidth limit, so this misreads the algorithm's behaviour when the primary member's measured throughput passes 100 Mbps.

  • ✓

    New sessions are sent to port2 until port1 drops below the threshold

    Why this is correct

    Spillover forwards new sessions to the second member once the primary member exceeds its threshold, while existing sessions stay on port1. At 120 Mbps, above the 100 Mbps threshold, port2 receives new sessions until port1 falls back below the limit.

  • ✗

    Port1 continues to receive all new sessions but packets are queued

    Why it's wrong here

    Spillover redirects new sessions to port2 when port1's throughput exceeds the threshold; it does not queue them on port1. Queuing describes traffic shaping or QoS egress limits, which buffer packets on a single interface rather than selecting an alternate SD-WAN member.

  • ✗

    New sessions are distributed equally between port1 and port2

    Why it's wrong here

    Spillover sends only the excess new sessions to port2 once port1 exceeds 100 Mbps; it does not rebalance evenly. Equal distribution describes the 'round-robin' or 'weighted round-robin' algorithms, which spread every new session across members regardless of current load.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.