Join the discussion
Question 26/27
Refer to the exhibit.
A FortiNAC-F N+1 HA configuration is shown.

What will occur if CA-2 fails?
A FortiNAC-F N+1 HA configuration is shown.

What will occur if CA-2 fails?
Correct Answer: B
In anN+1 High Availability (HA)configuration, a single secondary Control and Application (CA) server provides backup for multiple primary CA servers. The FortiNAC-F Manager (FortiNAC-M) acts as the centralized orchestrator for this cluster, monitoring the health of all participating nodes.
According to theFortiNAC-F 7.6.0 N+1 Failover Reference Manual, when a primary CA (such asCA-2in the exhibit) fails, the secondary CA (CA-3) is automatically promoted by the Manager to take over the specific workload and database functions of that failed primary. Crucially, the documentation specifies that even after this promotion, the system architecture maintains its N+1 logic. The secondary CA effectively " assumes the identity " of the failed primary while continuing to operate within the N+1 framework established by the Manager.
It doesnotmerge with CA-1 to form a traditional 1+1 active/passive cluster (A), nor does it engage in load balancing (D), as FortiNAC-F HA is designed for redundancy and failover rather than active traffic distribution. Furthermore, CA-3 does not " share " management with CA-1 (C); it independently handles the tasks originally assigned to CA-2. Throughout this failover state, the Manager continues to oversee the group, and CA-3 remains the designated secondary unit currently acting in a primary capacity for the downed node until CA-2 is restored.
" In an N+1 Failover Group, theSecondary CAis designed to take over the functionality ofany single failed primary componentwithin the group. The FortiNAC Manager monitors the primaries and initiates the failover to the secondary... Once failover occurs, the secondary continues to operate as the backup unit for the failed primary while remaining part of the managed N+1 HA configuration. " -FortiNAC-F 7.6.0 N+1 Failover Reference Manual: Failover Behavior Section.
According to theFortiNAC-F 7.6.0 N+1 Failover Reference Manual, when a primary CA (such asCA-2in the exhibit) fails, the secondary CA (CA-3) is automatically promoted by the Manager to take over the specific workload and database functions of that failed primary. Crucially, the documentation specifies that even after this promotion, the system architecture maintains its N+1 logic. The secondary CA effectively " assumes the identity " of the failed primary while continuing to operate within the N+1 framework established by the Manager.
It doesnotmerge with CA-1 to form a traditional 1+1 active/passive cluster (A), nor does it engage in load balancing (D), as FortiNAC-F HA is designed for redundancy and failover rather than active traffic distribution. Furthermore, CA-3 does not " share " management with CA-1 (C); it independently handles the tasks originally assigned to CA-2. Throughout this failover state, the Manager continues to oversee the group, and CA-3 remains the designated secondary unit currently acting in a primary capacity for the downed node until CA-2 is restored.
" In an N+1 Failover Group, theSecondary CAis designed to take over the functionality ofany single failed primary componentwithin the group. The FortiNAC Manager monitors the primaries and initiates the failover to the secondary... Once failover occurs, the secondary continues to operate as the backup unit for the failed primary while remaining part of the managed N+1 HA configuration. " -FortiNAC-F 7.6.0 N+1 Failover Reference Manual: Failover Behavior Section.
Add Comments
- Other Question (27q)
- Q1. During an evaluation of state-based enforcement, an administrator discovers that ports tha...
- Q2. Refer to the exhibit. (Exhibit) After a successful layer 2 poll, two hosts were learned on...
- Q3. Which two requirements must be met to set up an N+1 HA cluster? (Choose two.)...
- Q4. Which two actions must the administrator perform to allow FortiNAC-F to process incoming s...
- Q5. While deploying FortiNAC-F devices in a 1+1 HA configuration, the administrator has chosen...
- Q6. When creating a user or host profile, which three criteria can you apply? (Choose three.)...
- Q7. Refer to the exhibit. (Exhibit) If a host is connected to a port in the Building 1 First F...
- Q8. Refer to the exhibit. (Exhibit) An administrator wants to ensure that guest accounts creat...
- Q9. Refer to the exhibits. (Exhibit) What would happen if the highlighted port with connected ...
- Q10. While troubleshooting a network connectivity issue, an administrator determines that a dev...
- Q11. When configuring FortiNAC-F to manage FortiGate VPN users, an endpoint compliance policy m...
- Q12. An administrator wants to control user access to corporate resources by integrating FortiN...
- Q13. An administrator wants FortiNAC-F to pass firewall tags to FortiGate to leverage dynamic a...
- Q14. Two FortiNAC-F devices have been configured as a 1 + 1 HA pair. The primary server went of...
- Q15. Refer to the exhibit. (Exhibit) An administrator has configured the DHCP scope for a regis...
- Q16. An organization wants to add a FortiNAC-F Manager to simplify their large FortiNAC-F deplo...
- Q17. When working with a FortiNAC-F Manager and cluster management, what will occur when a clus...
- Q18. Refer to the exhibits. (Exhibit) An administrator is troubleshooting visibility issues on ...
- Q19. An administrator wants to create a conference manager administrator account but would like...
- Q20. Refer to the exhibit. (Exhibit) What would FortiNAC-F generate if only one of the security...
- Q21. Refer to the exhibit. (Exhibit) An administrator wants to use FortiNAC-F to automatically ...
- Q22. What must an administrator configure to allow FortiNAC-F to process incoming syslog messag...
- Q23. When preparing network infrastructure devices for visibility, what are the two main advant...
- Q24. A user was attempting to register their host through the registration captive portal. Afte...
- Q25. When managing multiple FortiNAC-F CAs with a FortiNAC-F Manager, how is endpoint informati...
- Q26. Refer to the exhibit. A FortiNAC-F N+1 HA configuration is shown. (Exhibit) What will occu...
- Q27. An administrator wants to build a security rule that will quarantine contractors who attem...
[×]
Download PDF File
Enter your email address to download Fortinet.NSE5_FNC_AD_7.6.v2026-07-18.q27.pdf
