NSE4 High Availability and Diagnostics Practice Question
A FortiGate administrator is troubleshooting a traffic issue where users cannot access a specific website. The administrator runs 'diagnose debug flow' and sees the output indicating that traffic is being denied by a firewall policy. Which two actions should the administrator take to identify the specific policy denying the traffic? (Choose two.)
⚠ Common exam trap
NSE4 often tests whether candidates know that debug flow output itself contains the policy ID, so they waste time on session list or disabling policies instead of reading the trace and correlating with logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the policy list and look for the policy ID shown in the debug output
Option C is correct because the 'diagnose debug flow' output explicitly prints the policy ID (e.g., 'matched policy 5') that denied the traffic, so reviewing the firewall policy list for that ID pinpoints the exact offending policy. Option D is correct because FortiGate traffic logs record the policy ID (policyid) for each session, so checking the log entry for the denied session reveals the same policy identifier and confirms which rule blocked the traffic. Option A is not the right action because 'diagnose debug enable' only turns on debug output; it does not itself identify the policy, and the administrator has already captured the flow output. Option B is incorrect because 'diagnose sys session list' shows session details such as source/destination and state, but it does not reliably surface the denying policy ID for a denied flow. Option E is incorrect and dangerous because disabling all firewall policies would remove security enforcement and is not a valid troubleshooting step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run 'diagnose debug enable' and then reproduce the issue
Why it's wrong here
Running 'diagnose debug enable' alone merely activates the debug buffer; without enabling 'diagnose debug flow' and setting appropriate filters (e.g., src-addr, dst-addr, port), it will not display the policy ID that the FortiGate used to evaluate the packets. Since the debug flow output already provides the policy ID for the matching traffic, enabling debug again is redundant and does not help isolate the specific policy causing the issue.
- ✗
Use 'diagnose sys session list' to find the policy ID
Why it's wrong here
The 'diagnose sys session list' command shows only currently established sessions in the session table, which are the result of traffic that was permitted and has an active state. If traffic is being denied by a policy, no session is created, so the denied session's policy ID will be absent from the session list. This command is useful for inspecting allowed flows but cannot reveal the policy ID that matched and denied a packet.
- ✓
Review the policy list and look for the policy ID shown in the debug output
Why this is correct
When you run 'diagnose debug flow', the output includes a log line that states the matching policy ID, for example "op=... policyid=..." for each packet. By reviewing the firewall policy list and looking up that specific policy ID, the administrator can directly inspect the action, schedule, source/destination addresses, and services configured on that policy to determine why it is handling the traffic unexpectedly.
- ✓
Check the traffic log for the session to see the policy ID
Why this is correct
FortiGate traffic logs record a "policyid" field for every session that matches a firewall policy, regardless of whether the action is "accept" or "deny". By querying the traffic log (either in the GUI under Log & Report or via CLI with 'get log traffic') and filtering for the offending session's timestamp or addresses, the administrator can identify the exact policy ID that processed the traffic. This log-based approach is useful when real-time debug is not available or when examining past incidents.
- ✗
Disable all firewall policies temporarily
Why it's wrong here
Disabling all firewall policies temporarily would put the FortiGate into an effective "allow all" mode for any explicit policy, but since the implicit deny policy at the end of the policy list remains, the behavior might not change significantly, and it introduces a severe security risk by exposing the network to unauthorized traffic. This brute-force method does not pinpoint the specific policy causing the issue and disrupts normal security posture; it should never be used for troubleshooting.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.