NSE7 Advanced Networking and SD-WAN Practice Question
An administrator configures a performance SLA for SD-WAN health checks. The SLA uses a ping probe to 8.8.8.8 every 2 seconds with a latency threshold of 150 ms and jitter threshold of 20 ms. After some time, the SD-WAN rule still shows the member as 'dead'. Which command should the administrator use to verify the probe results?
⚠ Common exam trap
Candidates often confuse the configuration display command ('show system sdwan health-check') with the diagnostic command ('diagnose sys sdwan health-check'), assuming the former shows live results when it only shows static configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose sys sdwan health-check
The 'diagnose sys sdwan health-check' command is the correct tool because it provides real-time, detailed probe results for each SD-WAN health-check member, including latency, jitter, packet loss, and SLA status. This allows the administrator to see exactly why the member is marked as 'dead', such as exceeding the 150 ms latency or 20 ms jitter thresholds. The 'show system sdwan health-check' command only displays configured parameters, not live probe data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
show system sdwan health-check
Why it's wrong here
This command displays SD-WAN health-check status and SLA metrics, but not the individual ping probe results the administrator needs. It is tempting because it is the natural first place to inspect SD-WAN health, and would be correct for checking overall member SLA state rather than per-probe latency and jitter values.
- ✓
diagnose sys sdwan health-check
Why this is correct
This command displays each SD-WAN member's health-check status, including latency and jitter values from the ping probes. Comparing those readings against the 150 ms and 20 ms thresholds reveals why the member is marked dead.
- ✗
diagnose sys session list
Why it's wrong here
Session listing shows firewall session table entries, not SD-WAN health-check probe latency or jitter measurements. It is tempting because sessions to 8.8.8.8 would appear there, and it would be correct for verifying whether probe traffic is being permitted or NATed rather than confirming probe results.
- ✗
execute ping-options source 8.8.8.8
Why it's wrong here
This sets the source address for a manual ping, which tests reachability but does not display the SLA probe's latency and jitter results. It is tempting because it mimics the health-check probe, and would be correct for manually confirming connectivity from a specific interface when troubleshooting reachability.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.