Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

An administrator configures two FortiGate units in an active-passive HA cluster. During a failover test, the administrator notices that the secondary unit becomes primary but the session table is empty, causing all existing connections to drop. Which configuration change should be made to preserve session information during failover?

⚠ Common exam trap

Test-takers frequently confuse configuration synchronization (which is automatic and covers settings) with session synchronization (which must be explicitly enabled), leading them to incorrectly select option A thinking it preserves sessions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable session pickup and configure HA session synchronization

Session pickup and HA session synchronization are specifically designed to replicate the session table from the primary FortiGate to the secondary unit in an active-passive cluster. Without this feature, the secondary unit becomes primary but has no knowledge of existing sessions, causing all active connections to drop. Enabling session synchronization ensures that session state information is continuously mirrored to the standby unit, allowing seamless failover without disrupting established flows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable FGCP configuration synchronization

    Why it's wrong here

    FGCP configuration synchronisation copies settings between cluster members, not live session state, so it cannot repopulate the secondary's session table; it is tempting because it is the standard HA sync setting, but preserving sessions across failover requires enabling session pickup (or connectionless session synchronisation) instead.

  • ✗

    Configure dead gateway detection on the FortiGate units

    Why it's wrong here

    Dead gateway detection only triggers failover when a gateway stops responding; it does not synchronise session state. Session preservation requires configuring session pickup (session synchronisation) between the cluster members, which replicates the session table to the secondary unit. Dead gateway detection is genuinely useful for detecting upstream link failures, not for HA state sharing.

  • ✗

    Enable link-failover on the monitored interfaces

    Why it's wrong here

    Enabling link-failover only controls when an interface failure triggers a failover; it does not synchronise connection state between cluster members. The empty session table stems from session-pickup being disabled, so existing flows cannot resume on the new primary. Link-failover is genuinely useful for detecting upstream path failures on monitored interfaces.

  • ✓

    Enable session pickup and configure HA session synchronization

    Why this is correct

    Session pickup forwards the primary's session table to the secondary, and HA session synchronization keeps TCP and UDP session state mirrored. Without both, the newly promoted unit has no existing sessions, so every established connection drops during failover.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.