Courseiva

NSE7 Troubleshooting and Diagnostics Practice Question

A network administrator runs 'get system ha status' on a FortiGate HA cluster and sees that only one unit shows as primary. The secondary unit shows as 'standalone' with no HA peer detected. What is the MOST likely cause of this issue?

⚠ Common exam trap

Watch out — candidates often confuse 'no HA peer detected' with configuration mismatches like serial numbers or group IDs, but those mismatches still allow peer detection and generate specific error messages, whereas a failed heartbeat link results in a complete lack of peer visibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The heartbeat interface is down or misconfigured

When a secondary unit shows as 'standalone' with no HA peer detected, it indicates that the heartbeat communication between the two FortiGate units has failed. The most common cause is that the heartbeat interface is down, misconfigured, or not physically connected, preventing the units from discovering each other as HA peers. Without a functioning heartbeat link, the secondary unit cannot join the cluster and remains in standalone mode.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The cluster serial numbers do not match

    Why it's wrong here

    FortiGate HA does not validate serial numbers for cluster formation, so differing serials never cause a standalone state; each unit legitimately has its own. Serial-based checks suit licence and support entitlement tracking, not HA peer negotiation.

  • ✓

    The heartbeat interface is down or misconfigured

    Why this is correct

    A secondary showing standalone means it never received HA heartbeat packets, so the cluster never formed. Heartbeat interfaces must be correctly cabled and configured on both units; if that link is down or mismatched, the peer is undetectable, producing exactly this split state.

  • ✗

    The HA group ID is different on each unit

    Why it's wrong here

    A mismatched group ID prevents the units from forming a cluster, so each runs independently and the peer is never detected. Matching group IDs suit intentional separation of multiple HA clusters on shared networks, not a single redundant pair.

  • ✗

    The HA priority on the secondary unit is set to 0

    Why it's wrong here

    Priority 0 only affects which unit becomes primary after election; it never stops a peer being detected. A standalone secondary indicates the HA heartbeat links are down or the cluster interfaces are misconfigured. Priority 0 is legitimately used to keep a unit as permanent standby, not to isolate it from the cluster.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.