20+ practice questions focused on Troubleshooting and Diagnostics — one of the most tested topics on the Fortinet NSE 7 Advanced Security NSE7 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Troubleshooting and Diagnostics PracticeA FortiGate administrator notices that traffic from a specific subnet is being dropped unexpectedly. The security policy allows the traffic, and there are no firewall policies blocking it. What is the most efficient first step to identify the cause of the drops?
Explanation: The 'diag sniffer packet any "host 10.0.1.0/24" 4' command captures packets at the kernel level before firewall processing, allowing you to see if traffic is reaching the FortiGate and where it is being dropped (e.g., due to reverse-path forwarding, session helper, or DoS policies). This is the most efficient first step because it provides immediate, low-level visibility into packet drops without requiring configuration changes or waiting for logs.
An organization uses FortiGate with OSPF and BGP. Recently, routes from BGP are not being preferred over OSPF routes, causing suboptimal routing. The administrator wants to ensure BGP routes are preferred. Which two actions can achieve this? (Choose two.)
Explanation: Option A is correct because FortiGate selects routes by administrative distance (AD) first, and lowering the BGP AD to 5 (below OSPF's default of 110) makes BGP routes win the best-route selection. Option C is correct because raising the OSPF administrative distance to 120 (above BGP's default of 20 for eBGP or 200 for iBGP, depending on the source) causes OSPF routes to lose to BGP routes in the RIB comparison. Option B is not correct because a route-map metric only influences BGP path selection among BGP routes (or is used for redistribution), not the AD-based comparison between BGP and OSPF. Option D is not correct because weight is a Cisco/BGP-specific attribute used only to prefer one BGP path over another BGP path, not to override OSPF routes on FortiGate.
An administrator is troubleshooting a VPN tunnel that is not coming up. The remote peer is a third-party device. Which THREE actions should be taken to diagnose the issue?
Explanation: Option A is correct because IKE Phase 1 authentication fails if the pre-shared key differs between peers, so verifying the PSK matches on both sides is essential when the tunnel won't come up. Option C is correct because basic IP reachability to the remote peer's public IP must exist before IKE can negotiate; if ping fails, the problem is at the network layer rather than in the VPN configuration. Option D is correct because 'diag debug application ike -1' enables verbose IKE debugging on FortiGate, exposing Phase 1/Phase 2 negotiation errors such as proposal mismatches or authentication failures. Option B is not among the marked answers; while UDP 500/4500 blocking is a common cause, it is not one of the three actions designated correct here. Option E is also not marked correct because routing to the remote subnet matters for traffic through an established tunnel, but it does not diagnose why the tunnel itself is failing to come up.
A FortiGate administrator sees the following kernel log: 'kernel: [pid 1234] received packet with unknown or unsupported protocol 0x0800 on interface port1, drop'. What does this log indicate?
Explanation: The kernel log indicates that the interface port1 received an Ethernet frame with EtherType 0x0800 (IPv4) but the FortiGate dropped it because the interface is either not configured with an IP address or is bound to the wrong VDOM. Without an IP address or proper VDOM assignment, the kernel cannot process the packet at Layer 3, so it logs the packet as having an 'unknown or unsupported protocol' even though 0x0800 is standard IPv4.
A FortiGate is experiencing high latency on traffic passing through it. The administrator suspects that asymmetric routing is occurring. Which TWO symptoms are indicative of asymmetric routing?
Explanation: Option B is correct because asymmetric routing specifically means that packets belonging to the same flow or from the same source can enter the FortiGate through different interfaces, which breaks stateful inspection and session tracking. Option E is correct because when return traffic takes a different path that bypasses the FortiGate, the firewall only sees the outbound TCP SYN and never observes the corresponding SYN-ACK, so the session remains incomplete and the application fails. Option A is not indicative of asymmetric routing, since multiple equal-cost paths in the routing table simply describe ECMP and do not by themselves mean traffic flows asymmetrically. Option C is not specific to asymmetric routing, as a policy can log traffic as allowed while the application still fails for many unrelated reasons such as NAT, MTU, or application-layer issues. Option D is not a symptom of asymmetric routing, because sustained high CPU during peak hours reflects resource load rather than a path asymmetry problem.
+15 more Troubleshooting and Diagnostics questions available
Practice all Troubleshooting and Diagnostics questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Troubleshooting and Diagnostics. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Troubleshooting and Diagnostics questions on the NSE7 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Troubleshooting and Diagnostics is tested as part of the Fortinet NSE 7 Advanced Security NSE7 blueprint. Practicing with targeted Troubleshooting and Diagnostics questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free NSE7 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Troubleshooting and Diagnostics is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Troubleshooting and Diagnostics practice session with instant scoring and detailed explanations.
Start Troubleshooting and Diagnostics Practice →