NSE7 Troubleshooting and Diagnostics Practice Question
An administrator runs 'diagnose debug application fnbam -1' and sees messages like 'LB_SELECT: selected server 10.0.0.2:80' but the client connection fails. The FortiGate is configured with server load balancing. What could be the issue?
⚠ Common exam trap
The trap here is that candidates see 'LB_SELECT' and assume the load-balancing decision is the problem, when in fact the debug output confirms the selection logic is working, and the failure lies in the server's reachability or health.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The real server is not reachable or is down
The 'LB_SELECT: selected server 10.0.0.2:80' message indicates that the FortiGate's load-balancing process has chosen a real server for the connection. However, the client connection fails, which points to a problem with the selected server itself. The most common cause is that the real server is unreachable or down, preventing the TCP handshake or HTTP response from completing, even though the load-balancing decision was made successfully.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The real server is not reachable or is down
Why this is correct
The debug shows the load balancer successfully selecting a real server, so the failure occurs after selection. If that server is down or unreachable, the client connection cannot complete, matching the symptom of selection succeeding but the connection failing.
- ✗
The load balancing algorithm is set to least-connection
Why it's wrong here
Least-connection is a valid distribution method and still selects a reachable server; the debug output confirms selection occurred, so the algorithm is not the fault. The failure sits after selection, such as the real server being marked down or unreachable. Least-connection would be chosen to balance load evenly across servers of differing capacity.
- ✗
The persistence setting is misconfigured
Why it's wrong here
Persistence only pins a client to a previously selected real server across separate connections; it does not affect whether the chosen server accepts the TCP handshake. The debug already shows a server selected, so the failure lies elsewhere, such as health-check status or routing. Persistence would be relevant when session affinity across requests is required.
- ✗
The virtual server IP is overlapping with a physical interface
Why it's wrong here
A virtual server IP overlapping a physical interface address causes the FortiGate to treat the VIP as a local address, so return traffic is not load-balanced and the client connection fails. Overlap is a genuine misconfiguration, but the log shows server selection succeeding, so the fault lies after selection, in the backend server or health check.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.