NSE4 High Availability and Diagnostics Practice Question
A FortiGate administrator is investigating a performance issue and suspects that a large number of incomplete TCP connections are consuming session table resources. Which TWO commands would help identify such sessions? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose sys session stat
Diagnose sys session list with filter can show sessions by state. Diagnose sys session stat shows counts by state. The sniffer shows packets, not session state; debug flow is for tracing specific streams.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
diagnose debug flow filter dport 80 ; diagnose debug enable
Why it's wrong here
The command pair `diagnose debug flow filter dport 80` combined with `diagnose debug enable` enables per-packet flow tracing for traffic destined to port 80. This outputs a verbose log of each packet's path through the firewall engine, including attribute lookups and policy hits, which is useful for troubleshooting a single session, not for assessing aggregate session table health. For a performance issue stemming from many incomplete sessions, this would flood the console with granular data and obscure the overall count, so it is not an efficient diagnostic step.
- ✓
diagnose sys session stat
Why this is correct
`diagnose sys session stat` is the correct first command because it presents a concise summary of session table statistics, including totals for sessions in various states such as TCP SYN-SENT, SYN-RECV, ESTABLISHED, FIN-WAIT, and others. By observing an unusually high count in the SYN-SENT bucket, an administrator can quickly confirm whether incomplete (half-open) connections are accumulating and contributing to the performance problem. This aggregate view is fast, non-intrusive, and gives immediate insight into the session table distribution without listing individual sessions.
- ✗
diagnose sniffer packet any 'tcp' 4
Why it's wrong here
`diagnose sniffer packet any 'tcp' 4` captures raw TCP packets on the interface, displaying packet headers and payload excerpts rather than session table entries. While a packet capture could reveal repeated SYN retransmissions or missing ACKs, it requires manual analysis to correlate captures with session states and does not provide a direct count or status of sessions in the kernel table. It is also resource-intensive in a production environment and does not help pinpoint whether the issue is in the session table itself, making it a poor choice for this investigation.
- ✓
diagnose sys session filter state syn-sent ; diagnose sys session list
Why this is correct
`diagnose sys session filter state syn-sent` followed by `diagnose sys session list` is another valid approach because it filters the session table to show only sessions currently in the SYN-SENT state, which represents incomplete TCP connections awaiting a SYN-ACK. Listing these sessions individually allows the administrator to examine source/destination IPs, ports, and the age of each half-open session, helping to identify the source of an attack or misconfiguration. Unlike the aggregate `stat` command, this provides detailed per-session information, but it is still a correct diagnostic tool for correlating performance issues with incomplete connections.
- ✗
diagnose sys session filter proto 6 ; diagnose sys session list
Why it's wrong here
`diagnose sys session filter proto 6` with `diagnose sys session list` filters sessions by IP protocol number 6 (TCP) but does not narrow by session state. This would output every TCP session in the table, including established and closing sessions, swamping the administrator with data and making it impossible to distinguish incomplete connections from normal traffic. Because the performance issue is specifically tied to incomplete sessions, this command lacks the necessary state filter and is thus not an appropriate diagnostic for the described problem.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.