NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator configures two FortiGate units in an active-passive HA cluster. During a failover test, the administrator notices that the secondary unit becomes primary but the session table is empty, causing all existing connections to drop. Which configuration change should be made to preserve session information during failover?
⚠ Common exam trap
Test-takers frequently confuse configuration synchronization (which is automatic and covers settings) with session synchronization (which must be explicitly enabled), leading them to incorrectly select option A thinking it preserves sessions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable session pickup and configure HA session synchronization
Session pickup and HA session synchronization are specifically designed to replicate the session table from the primary FortiGate to the secondary unit in an active-passive cluster. Without this feature, the secondary unit becomes primary but has no knowledge of existing sessions, causing all active connections to drop. Enabling session synchronization ensures that session state information is continuously mirrored to the standby unit, allowing seamless failover without disrupting established flows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable FGCP configuration synchronization
Why it's wrong here
FGCP configuration synchronisation copies settings between cluster members, not live session state, so it cannot repopulate the secondary's session table; it is tempting because it is the standard HA sync setting, but preserving sessions across failover requires enabling session pickup (or connectionless session synchronisation) instead.
- ✗
Configure dead gateway detection on the FortiGate units
Why it's wrong here
Dead gateway detection only triggers failover when a gateway stops responding; it does not synchronise session state. Session preservation requires configuring session pickup (session synchronisation) between the cluster members, which replicates the session table to the secondary unit. Dead gateway detection is genuinely useful for detecting upstream link failures, not for HA state sharing.
- ✗
Enable link-failover on the monitored interfaces
Why it's wrong here
Enabling link-failover only controls when an interface failure triggers a failover; it does not synchronise connection state between cluster members. The empty session table stems from session-pickup being disabled, so existing flows cannot resume on the new primary. Link-failover is genuinely useful for detecting upstream path failures on monitored interfaces.
- ✓
Enable session pickup and configure HA session synchronization
Why this is correct
Session pickup forwards the primary's session table to the secondary, and HA session synchronization keeps TCP and UDP session state mirrored. Without both, the newly promoted unit has no existing sessions, so every established connection drops during failover.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.