NSE7 Advanced Networking and SD-WAN Practice Question
Which THREE statements are true about FortiGate SD-WAN health-check configuration?
⚠ Common exam trap
Many candidates assume health-check can use any interface as a source (like loopback) or that it only works on physical interfaces, but FortiGate restricts probe source to the member interface and supports VLANs and aggregates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Health-check can be configured with multiple thresholds for jitter, latency, and packet loss.
Option C is correct because FortiGate SD-WAN health checks support SLA targets with separate thresholds for latency, jitter, and packet loss, allowing each performance metric to be evaluated independently. Option D is correct because the 'update-static-route' setting (enabled by default) lets the health check dynamically remove or restore a static route when the link's SLA is violated or recovered, providing automatic fallback. Option E is correct because SD-WAN health checks can use several probe protocols, including ping, TCP echo, HTTP, and DNS, to verify end-to-end link health beyond simple ICMP. Option A is incorrect because health-check probes must be sourced from the interface being monitored, not from arbitrary interfaces such as a loopback. Option B is incorrect because health checks can be applied to VLANs and subinterfaces, not only physical interfaces.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Health-check probes can be sent from any interface, including loopback.
Why it's wrong here
Health-check probes require a routable source address and are not sent from loopback interfaces, so this statement is false. It is tempting because loopback interfaces are stable and always up, and would be valid for services such as BGP router-ID or management access that do not depend on probe traffic.
- ✗
Health-check can only be configured on physical interfaces, not VLANs or subinterfaces.
Why it's wrong here
SD-WAN health-checks bind to any interface with an IP address, including VLANs and subinterfaces, so this restriction is false. It is tempting because physical-interface-only assumptions echo older link-monitor behaviour, and would hold in designs where health-checks were historically tied to WAN physical ports.
- ✓
Health-check can be configured with multiple thresholds for jitter, latency, and packet loss.
Why this is correct
SD-WAN health checks support separate SLA thresholds for latency, jitter and packet loss, and each member can be assigned multiple threshold values to define acceptable performance bands. This lets FortiGate mark a link degraded or dead when any measured metric breaches its configured limit.
- ✓
Health-check can update the routing table by setting 'update-static-route' to enable fallback.
Why this is correct
With update-static-route enabled, the health-check dynamically adds or withdraws the static route associated with the SD-WAN member, so traffic fails over to a healthy link when the monitored link goes down, providing the fallback behaviour described.
- ✓
Health-check can be configured to use HTTP or DNS protocols to verify link health.
Why this is correct
Health-check probes support several protocols, including HTTP and DNS, alongside ICMP and TCP echo. Using HTTP or DNS lets the check verify application-layer reachability rather than mere ICMP responsiveness, confirming the link can serve real traffic.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.