NSE7 Troubleshooting and Diagnostics Practice Question
You are troubleshooting an SD-WAN rule where traffic is not matching the expected SLA. The FortiGate shows 'SLA mismatch' in logs. What is the MOST likely cause?
⚠ Common exam trap
Test-takers frequently confuse 'SLA mismatch' with a connectivity issue (interface down or probe unreachable), but the log specifically indicates that the link is up and probes are responding, just not within the acceptable performance thresholds.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The measured SLA values exceed the configured thresholds
The 'SLA mismatch' log indicates that the measured SLA values (e.g., jitter, latency, packet loss) for the traffic have exceeded the configured thresholds in the SD-WAN rule. This causes the FortiGate to consider the link as not meeting the SLA, even though the interface is up and the probe server is reachable. The SD-WAN rule itself is enabled, but the traffic is steered away from the preferred member because the SLA is not satisfied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The interface is down
Why it's wrong here
An interface being down removes that member from selection entirely, producing a different log state than an SLA breach; 'SLA mismatch' indicates the chosen member's measured performance exceeded configured thresholds. Interface-down diagnosis applies when SD-WAN members drop out of the health-check table.
- ✗
The SLA probe server is unreachable
Why it's wrong here
An unreachable probe server causes health-check failures, but 'SLA mismatch' specifically means measured latency, jitter or packet loss exceeded the configured thresholds on the selected member. Probe reachability is the correct diagnosis when members show as down rather than breaching SLA targets.
- ✓
The measured SLA values exceed the configured thresholds
Why this is correct
FortiGate compares each member's measured latency, jitter and packet loss against the SLA thresholds configured in the SD-WAN rule. When those measurements exceed the thresholds, the rule reports SLA mismatch and steers traffic to another member.
- ✗
The SD-WAN rule is not enabled
Why it's wrong here
A disabled SD-WAN rule would produce no match at all, so no SLA verdict would be logged; 'SLA mismatch' means the rule matched but no member met the configured latency, jitter or packet-loss thresholds. Disabling rules is used when decommissioning or temporarily bypassing a path.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.