NSE7 Troubleshooting and Diagnostics Practice Question
During a failover test in an HA cluster, the primary FortiGate fails over to the secondary. After failover, some existing TCP sessions are dropped. What is the MOST likely reason?
⚠ Common exam trap
Candidates often assume active-passive HA always drops sessions or that routing changes are the default cause, but Fortinet specifically tests that session pickup must be explicitly enabled to preserve TCP sessions during failover.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session pickup is not enabled on the HA cluster
In an HA cluster, session pickup (also known as session synchronization) is responsible for replicating session tables from the primary FortiGate to the secondary. When failover occurs, if session pickup is not enabled, the secondary FortiGate has no knowledge of existing TCP sessions, causing them to be dropped. This is the most likely reason because the secondary device cannot forward traffic for sessions it does not recognize, even if the network topology remains unchanged.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The failover caused a routing change
Why it's wrong here
Routing reconvergence affects path selection for new flows; existing TCP sessions drop because the secondary FortiGate has no synchronised session table entries, not because routes changed. It is tempting as routing does shift on failover, but that would explain new-connection failures, not established-session loss.
- ✗
The session TTL expired during failover
Why it's wrong here
Session TTL governs idle timeout, not failover survival; established sessions are dropped because the secondary lacks their synchronised state, not because a timer elapsed. It is tempting since TTL expiry does close sessions, but that would be the answer if sessions were idle, not after a failover event.
- ✗
The HA mode is active-passive
Why it's wrong here
Active-passive is the HA mode itself, not a cause; sessions drop because the secondary lacks synchronised session state for those flows. It is tempting since active-passive failover does interrupt traffic, but that would be the answer if the question asked which mode causes disruption, not why sessions drop.
- ✓
Session pickup is not enabled on the HA cluster
Why this is correct
Without session pickup, the secondary FortiGate has no synchronised session table, so established TCP flows cannot be matched after failover and are dropped. Enabling session pickup replicates session state, preserving existing connections across the failover event.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.