Courseiva

NSE7 Advanced Networking and SD-WAN Practice Question

An administrator has configured a FortiGate with an SD-WAN zone named 'virtual-wan-link' containing two members: port1 (WAN1) and port2 (WAN2). A performance SLA named 'CriticalSLA' monitors a server at 8.8.8.8 using ICMP probes every 5 seconds, with failure thresholds: latency 200 ms, jitter 50 ms, packet loss 5%. The SLA status for port1 is 'alive' and for port2 is 'dead'. An SD-WAN rule is configured to use the 'lowest-cost' algorithm with the SLA target 'CriticalSLA'. The administrator notices that all traffic is being routed through port1, even though port2 has a lower cost metric. What is the most likely reason for this behavior?

⚠ Common exam trap

The trap here is assuming that the lowest-cost algorithm ignores SLA status and simply picks the member with the lowest configured cost.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SD-WAN rule is configured with the 'lowest-cost' algorithm, which only selects members that meet the SLA target; port2 is excluded because it is dead.

The lowest-cost algorithm selects the member with the lowest cost among those that meet the SLA target. Since port2 is dead, it is excluded from selection, leaving port1 as the only eligible member. This ensures traffic only uses links that meet the performance requirements. The cost metric is only considered after filtering by SLA status.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The SD-WAN rule is configured with the 'lowest-cost' algorithm, which only selects members that meet the SLA target; port2 is excluded because it is dead.

    Why this is correct

    The lowest-cost algorithm selects the member with the lowest cost among those that meet the SLA target. Since port2 is dead, it does not meet the SLA and is excluded. Port1, being alive, is the only eligible member, so all traffic uses port1. This is the expected behavior: SLA status takes precedence over cost.

  • ✗

    The performance SLA is using ICMP probes, which are not supported for SLA monitoring; the FortiGate falls back to using only port1.

    Why it's wrong here

    ICMP probes are supported for performance SLA monitoring on FortiGate. The SLA can use ICMP, TCP, UDP, or HTTP. The issue is not the probe type but the SLA status. If ICMP were unsupported, the SLA would not function at all, but here it shows port1 alive and port2 dead, indicating ICMP is working.

  • ✗

    The SD-WAN rule is missing a priority configuration; without priority, the FortiGate defaults to using the first member in the zone.

    Why it's wrong here

    SD-WAN rules do not use a priority setting to determine member selection; they use algorithms like lowest-cost, volume, or source-ip-based. The default behavior without an SD-WAN rule might use the first member, but with a rule using lowest-cost, the algorithm dynamically selects based on cost and SLA. Priority is not a factor here.

  • ✗

    The 'lowest-cost' algorithm only considers the configured cost of each member, and port2 has a higher cost than port1.

    Why it's wrong here

    The lowest-cost algorithm in SD-WAN does consider the configured cost, but it also requires the member to meet the SLA target. If port2 is dead, it is excluded regardless of cost. However, the scenario states that port2 has a lower cost metric, so this option contradicts the given information. The algorithm does not ignore SLA status; it prioritizes members that meet the SLA.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.