NSE7 Advanced Networking and SD-WAN Practice Question
Which of the following is the primary purpose of BFD (Bidirectional Forwarding Detection) on a FortiGate?
⚠ Common exam trap
Many exam-takers confuse BFD with routing protocol keepalives or assume it performs routing table synchronization, when in fact BFD is purely a fast failure detection mechanism that operates independently of the routing protocol.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To provide fast detection of link failures
BFD (Bidirectional Forwarding Detection) is a lightweight protocol designed to provide sub-second failure detection between two forwarding engines, such as FortiGate peers. Unlike routing protocol hellos (e.g., OSPF Hello at 10-second intervals), BFD can detect link or neighbor failures in as little as 50–100 ms, enabling faster convergence. This makes it the primary mechanism for rapid link failure detection in high-availability and SD-WAN deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To synchronize routing tables between peers
Why it's wrong here
BFD provides fast liveness detection of a forwarding path; routing table synchronisation is performed by the routing protocol itself, such as OSPF or BGP. It is tempting because BFD state changes trigger route recalculation, but BFD carries no routing prefixes or topology information.
- ✗
To load balance traffic across multiple paths
Why it's wrong here
BFD detects link failures rapidly between forwarding engines; it does not distribute traffic across paths, which ECMP or SD-WAN rules handle. It is tempting because sub-second failure detection often accompanies load-balanced topologies, but BFD itself only signals adjacency state to routing protocols.
- ✓
To provide fast detection of link failures
Why this is correct
BFD sends rapid heartbeat packets between neighbouring devices, detecting link or path failures in milliseconds rather than waiting for routing protocol timers. This fast failure detection lets the FortiGate reconverge traffic quickly, which is BFD's primary purpose.
- ✗
To encrypt routing updates between peers
Why it's wrong here
BFD packets are unencrypted and carry only detection timers and state; confidentiality of routing updates is provided by IPsec or TCP-AO/MD5 authentication. It is tempting because BFD often runs alongside IPsec-protected tunnels, but BFD itself performs no cryptographic operations.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.