Courseiva

NSE7 Troubleshooting and Diagnostics Practice Question

During a failover test in an HA cluster, the primary FortiGate fails over to the secondary. After failover, some existing TCP sessions are dropped. What is the MOST likely reason?

⚠ Common exam trap

Candidates often assume active-passive HA always drops sessions or that routing changes are the default cause, but Fortinet specifically tests that session pickup must be explicitly enabled to preserve TCP sessions during failover.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Session pickup is not enabled on the HA cluster

In an HA cluster, session pickup (also known as session synchronization) is responsible for replicating session tables from the primary FortiGate to the secondary. When failover occurs, if session pickup is not enabled, the secondary FortiGate has no knowledge of existing TCP sessions, causing them to be dropped. This is the most likely reason because the secondary device cannot forward traffic for sessions it does not recognize, even if the network topology remains unchanged.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The failover caused a routing change

    Why it's wrong here

    Routing reconvergence affects path selection for new flows; existing TCP sessions drop because the secondary FortiGate has no synchronised session table entries, not because routes changed. It is tempting as routing does shift on failover, but that would explain new-connection failures, not established-session loss.

  • ✗

    The session TTL expired during failover

    Why it's wrong here

    Session TTL governs idle timeout, not failover survival; established sessions are dropped because the secondary lacks their synchronised state, not because a timer elapsed. It is tempting since TTL expiry does close sessions, but that would be the answer if sessions were idle, not after a failover event.

  • ✗

    The HA mode is active-passive

    Why it's wrong here

    Active-passive is the HA mode itself, not a cause; sessions drop because the secondary lacks synchronised session state for those flows. It is tempting since active-passive failover does interrupt traffic, but that would be the answer if the question asked which mode causes disruption, not why sessions drop.

  • ✓

    Session pickup is not enabled on the HA cluster

    Why this is correct

    Without session pickup, the secondary FortiGate has no synchronised session table, so established TCP flows cannot be matched after failover and are dropped. Enabling session pickup replicates session state, preserving existing connections across the failover event.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.