Courseiva

NSE7 Advanced Networking and SD-WAN Practice Question

An administrator wants to integrate a FortiExtender into an existing SD-WAN deployment. Which TWO steps are required for proper integration?

⚠ Common exam trap

Watch out — candidates often assume the FortiExtender requires a separate VDOM or NAT configuration, when in fact it simply needs authorization and SD-WAN membership to function as a standard WAN interface within the existing SD-WAN topology.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authorize the FortiExtender on the FortiGate

The FortiExtender must first be authorized on the FortiGate to establish a secure management and data plane connection. Once authorized, it must be added as an SD-WAN member interface so that SD-WAN rules and load-balancing algorithms can be applied to traffic traversing the FortiExtender's cellular or LTE link.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable all other WAN interfaces

    Why it's wrong here

    Disabling other WAN interfaces contradicts SD-WAN's purpose: multiple links participate simultaneously, with FortiExtender added as an additional member interface. The tempting logic is that a single active uplink simplifies routing, which suits a failover-only or standalone FortiExtender deployment without SD-WAN. Integration instead requires configuring the extender as an SD-WAN member and applying health checks.

  • ✓

    Authorize the FortiExtender on the FortiGate

    Why this is correct

    Authorising the FortiExtender on the FortiGate establishes the management trust relationship, letting the FortiGate discover, provision and monitor the extender as an SD-WAN member interface. Without this authorisation step, the FortiExtender cannot join the SD-WAN fabric or participate in path selection.

  • ✗

    Enable NAT on the FortiExtender interface

    Why it's wrong here

    Enabling NAT on the FortiExtender interface is unnecessary because FortiExtender operates as a Layer 2 bridge or Layer 3 gateway managed by FortiGate, which already handles NAT for WAN traffic. NAT would be tempting when the FortiExtender connects standalone clients directly to a cellular uplink without a FortiGate managing address translation.

  • ✗

    Configure a separate VDOM for the FortiExtender

    Why it's wrong here

    A separate VDOM isolates the FortiExtender's management and traffic from the SD-WAN fabric, so the extender cannot participate in the existing SD-WAN rules, health checks or overlay. VDOMs suit multi-tenant or administrative separation, not extending an existing SD-WAN deployment, where the extender joins the current VDOM's SD-WAN configuration.

  • ✓

    Configure the FortiExtender as an SD-WAN member

    Why this is correct

    Adding the FortiExtender as an SD-WAN member lets FortiGate steer traffic across its WWAN link alongside existing WAN members, satisfying the stem's requirement for integration into the SD-WAN fabric. Without membership, the extender's link cannot participate in SD-WAN rules, health checks or failover.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.