Courseiva

NSE7 Advanced Networking and SD-WAN Practice Question

An administrator configures a performance SLA for SD-WAN health checks. The SLA uses a ping probe to 8.8.8.8 every 2 seconds with a latency threshold of 150 ms and jitter threshold of 20 ms. After some time, the SD-WAN rule still shows the member as 'dead'. Which command should the administrator use to verify the probe results?

⚠ Common exam trap

Candidates often confuse the configuration display command ('show system sdwan health-check') with the diagnostic command ('diagnose sys sdwan health-check'), assuming the former shows live results when it only shows static configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose sys sdwan health-check

The 'diagnose sys sdwan health-check' command is the correct tool because it provides real-time, detailed probe results for each SD-WAN health-check member, including latency, jitter, packet loss, and SLA status. This allows the administrator to see exactly why the member is marked as 'dead', such as exceeding the 150 ms latency or 20 ms jitter thresholds. The 'show system sdwan health-check' command only displays configured parameters, not live probe data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    show system sdwan health-check

    Why it's wrong here

    This command displays SD-WAN health-check status and SLA metrics, but not the individual ping probe results the administrator needs. It is tempting because it is the natural first place to inspect SD-WAN health, and would be correct for checking overall member SLA state rather than per-probe latency and jitter values.

  • ✓

    diagnose sys sdwan health-check

    Why this is correct

    This command displays each SD-WAN member's health-check status, including latency and jitter values from the ping probes. Comparing those readings against the 150 ms and 20 ms thresholds reveals why the member is marked dead.

  • ✗

    diagnose sys session list

    Why it's wrong here

    Session listing shows firewall session table entries, not SD-WAN health-check probe latency or jitter measurements. It is tempting because sessions to 8.8.8.8 would appear there, and it would be correct for verifying whether probe traffic is being permitted or NATed rather than confirming probe results.

  • ✗

    execute ping-options source 8.8.8.8

    Why it's wrong here

    This sets the source address for a manual ping, which tests reachability but does not display the SLA probe's latency and jitter results. It is tempting because it mimics the health-check probe, and would be correct for manually confirming connectivity from a specific interface when troubleshooting reachability.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.