Courseiva

NSE7 Advanced Networking and SD-WAN Practice Question

A network administrator is troubleshooting an SD-WAN setup where a specific application is not using the intended overlay tunnel. The SD-WAN rule is configured with a destination of 'all' and a source of 'all', and the strategy is set to 'manual' with the overlay tunnel as the preferred member. However, traffic is still going out via the underlay. What is the most likely reason?

⚠ Common exam trap

The trap here is assuming that manual strategy ignores member health and always uses the preferred member, when in fact it falls back if the member is unhealthy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The overlay tunnel member is down or not meeting the SLA, so the rule falls back to the underlay.

When an SD-WAN rule uses a manual strategy with a preferred member, the FortiGate will use that member if it is available and healthy. If the member is down or fails its SLA, the rule will fall back to other members, such as the underlay. Thus, the most likely reason for traffic using the underlay is that the overlay member is not available or not meeting the SLA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The 'manual' strategy requires a gateway to be specified for the preferred member.

    Why it's wrong here

    The 'manual' strategy simply uses the order of members as listed in the rule. It does not require a gateway. The members are selected in the order they appear. If the first member is available, it is used. Specifying a gateway is not part of the manual strategy configuration.

  • ✓

    The overlay tunnel member is down or not meeting the SLA, so the rule falls back to the underlay.

    Why this is correct

    If the preferred overlay member is down or fails its performance SLA, the SD-WAN rule may fall back to other available members, such as the underlay. This is a common cause of traffic not using the intended tunnel. Checking the member's status and SLA results is essential.

  • ✗

    The SD-WAN rule is placed below a static route that directs traffic to the underlay.

    Why it's wrong here

    SD-WAN rules are evaluated before the routing table. A static route would not override an SD-WAN rule. The order of evaluation is: SD-WAN rules first, then policy routes, then routing table. Therefore, a static route below would not cause traffic to bypass the SD-WAN rule.

  • ✗

    The SD-WAN rule is missing a matching service or application, so it does not match the traffic.

    Why it's wrong here

    The rule is configured with source and destination 'all', so it should match all traffic. If a service or application were specified, it would narrow the match, but its absence would not prevent matching. The issue is more likely related to the rule's position or the member's status. Therefore, this is not the cause.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.