NSE7 Advanced Networking and SD-WAN Practice Question
An administrator wants to integrate a FortiExtender into an existing SD-WAN deployment. Which TWO steps are required for proper integration?
⚠ Common exam trap
Watch out — candidates often assume the FortiExtender requires a separate VDOM or NAT configuration, when in fact it simply needs authorization and SD-WAN membership to function as a standard WAN interface within the existing SD-WAN topology.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorize the FortiExtender on the FortiGate
The FortiExtender must first be authorized on the FortiGate to establish a secure management and data plane connection. Once authorized, it must be added as an SD-WAN member interface so that SD-WAN rules and load-balancing algorithms can be applied to traffic traversing the FortiExtender's cellular or LTE link.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable all other WAN interfaces
Why it's wrong here
Disabling other WAN interfaces contradicts SD-WAN's purpose: multiple links participate simultaneously, with FortiExtender added as an additional member interface. The tempting logic is that a single active uplink simplifies routing, which suits a failover-only or standalone FortiExtender deployment without SD-WAN. Integration instead requires configuring the extender as an SD-WAN member and applying health checks.
- ✓
Authorize the FortiExtender on the FortiGate
Why this is correct
Authorising the FortiExtender on the FortiGate establishes the management trust relationship, letting the FortiGate discover, provision and monitor the extender as an SD-WAN member interface. Without this authorisation step, the FortiExtender cannot join the SD-WAN fabric or participate in path selection.
- ✗
Enable NAT on the FortiExtender interface
Why it's wrong here
Enabling NAT on the FortiExtender interface is unnecessary because FortiExtender operates as a Layer 2 bridge or Layer 3 gateway managed by FortiGate, which already handles NAT for WAN traffic. NAT would be tempting when the FortiExtender connects standalone clients directly to a cellular uplink without a FortiGate managing address translation.
- ✗
Configure a separate VDOM for the FortiExtender
Why it's wrong here
A separate VDOM isolates the FortiExtender's management and traffic from the SD-WAN fabric, so the extender cannot participate in the existing SD-WAN rules, health checks or overlay. VDOMs suit multi-tenant or administrative separation, not extending an existing SD-WAN deployment, where the extender joins the current VDOM's SD-WAN configuration.
- ✓
Configure the FortiExtender as an SD-WAN member
Why this is correct
Adding the FortiExtender as an SD-WAN member lets FortiGate steer traffic across its WWAN link alongside existing WAN members, satisfying the stem's requirement for integration into the SD-WAN fabric. Without membership, the extender's link cannot participate in SD-WAN rules, health checks or failover.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.