Courseiva

NSE4 High Availability and Diagnostics Practice Question

A FortiGate administrator is diagnosing a performance issue. They notice that the CPU usage is consistently high. Which command can provide a real-time view of the processes consuming CPU?

⚠ Common exam trap

NSE4 often tests the distinction between summary performance commands ('get system performance status') and live per-process monitoring ('diagnose sys top'), so candidates choose the summary command thinking it shows process-level detail.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose sys top

'diagnose sys top' provides a real-time, top-like view of running processes on the FortiGate, sorted by CPU and memory consumption, refreshing periodically. It is the correct tool to identify which specific process (e.g., ipsengine, wad, scanunitd) is driving sustained high CPU. This directly answers the need for a live process-level CPU view.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    get system performance status

    Why it's wrong here

    This command gives a system-wide snapshot of overall CPU and memory utilization, but it aggregates all processes together. It does not identify which individual process is consuming the most CPU, so it is insufficient for diagnosing a process-level performance bottleneck. While it can indicate whether the system is under heavy load, it cannot reveal the specific daemon or service responsible.

  • ✗

    diagnose sys session stat

    Why it's wrong here

    This command reports on the session table, including total sessions, session setup rates, and memory allocated to session management. It focuses on the FortiGate's connection-tracking state rather than the CPU consumption of individual processes. While it could reveal a session-related resource issue, it does not provide the per-process CPU breakdown needed to locate the root cause of a performance degradation.

  • ✗

    diagnose debug flow

    Why it's wrong here

    This is a packet-tracing utility that logs the forwarding path of specific traffic flows, showing where packets are dropped or accepted at each policy and routing stage. It is primarily useful for debugging firewall policy, NAT, or routing problems, but it does not report process CPU usage. This command operates on the data plane's packet-processing path, not on the host operating system's process scheduler, so it cannot identify a process consuming CPU.

  • ✓

    diagnose sys top

    Why this is correct

    This command functions like the Linux 'top' utility, presenting a real-time, updating list of FortiOS processes with per-process CPU and memory consumption. It is the correct tool for identifying which specific process is causing high CPU during a performance issue. By observing the process list, an administrator can pinpoint the culprit, such as an overactive log daemon or the antivirus scanning engine, and take targeted action.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.