NSE7 Advanced Networking and SD-WAN Practice Question
An administrator is troubleshooting an SD-WAN rule that is not matching traffic as expected. The rule is configured with a source address of 'all', destination '10.0.0.0/24', and service 'HTTP'. The rule is placed after a rule that matches all traffic to '10.0.0.0/24' with service 'ALL'. The administrator notices that HTTP traffic to 10.0.0.0/24 is being handled by the first rule. What is the most likely cause?
⚠ Common exam trap
The trap here is assuming that SD-WAN rules use a most-specific-match logic like firewall policies, when in fact they are order-dependent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SD-WAN rules are evaluated in order, and the first matching rule is applied. The rule with service 'ALL' matches HTTP traffic, so it takes precedence.
SD-WAN rules are processed in the order they are listed, and the first rule that matches the traffic is used. In this case, the rule with service 'ALL' matches HTTP traffic before the HTTP-specific rule is evaluated. The solution is to move the HTTP rule above the generic rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The SD-WAN rule with service 'ALL' has a higher priority value, which overrides the order of rules.
Why it's wrong here
SD-WAN rules do not have a separate priority value that overrides order; they are evaluated sequentially. The order in the list determines precedence. There is no priority field that changes this behavior. Thus, this is not the cause.
- ✓
SD-WAN rules are evaluated in order, and the first matching rule is applied. The rule with service 'ALL' matches HTTP traffic, so it takes precedence.
Why this is correct
SD-WAN rules are evaluated sequentially from top to bottom. The first rule matches all services, including HTTP, so it captures the traffic before the more specific rule is evaluated. To fix this, the administrator should reorder the rules so that the HTTP-specific rule is above the generic rule.
- ✗
The HTTP rule is not matching because the service 'HTTP' is not defined in the SD-WAN rule; the administrator must use 'ALL' for web traffic.
Why it's wrong here
FortiGate supports predefined services such as 'HTTP' in SD-WAN rules. The issue is not the service definition but the rule order. The HTTP rule would match if it were evaluated first. Therefore, this is not the cause.
- ✗
SD-WAN rules are evaluated based on the most specific match, so the HTTP rule should take precedence regardless of order.
Why it's wrong here
FortiGate SD-WAN rules do not use a most-specific-match logic; they are evaluated in the order they appear in the configuration. The first matching rule is applied. Therefore, the HTTP rule will not take precedence if it is below a rule that matches all services.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.