Courseiva

NSE4 High Availability and Diagnostics Practice Question

A FortiGate administrator is troubleshooting an issue where HTTPS traffic is not being properly inspected by the web filter. The policy has SSL inspection enabled. Which TWO commands would provide the most useful real-time debugging information? (Choose two.)

⚠ Common exam trap

NSE4 often tests the specific debug commands for SSL inspection, and candidates may choose session list or logs instead of real-time debug flow and sniffer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose debug flow filter dport 443 ; diagnose debug flow show function-name ; diagnose debug enable

Option B is correct because the debug flow commands (diagnose debug flow filter dport 443, diagnose debug flow show function-name, diagnose debug enable) provide real-time packet-path tracing that shows whether the HTTPS session is being matched to the firewall policy and whether SSL inspection is applied, which is essential for troubleshooting web-filter inspection issues. Option E is correct because diagnose sniffer packet any 'port 443' 4 captures live packets on port 443 with interface information, allowing the administrator to verify that HTTPS traffic is actually reaching the FortiGate and to observe the handshake behavior in real time. Option A is not appropriate because diagnose test application ips 1 only tests IPS engine operation and does not trace HTTPS web-filter or SSL-inspection processing. Option C is not the best choice because diagnose sys session filter dport 443 with diagnose sys session list only shows the session table entries and does not provide real-time debugging of the inspection path. Option D is not suitable because execute log display only shows already-generated log entries and does not deliver live debugging information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    diagnose test application ips 1

    Why it's wrong here

    This command triggers a diagnostic self-test of the IPS engine, verifying signature database integrity and engine responsiveness, rather than tracing HTTPS traffic. Because the symptom is about HTTPS inspection—likely SSL/TLS decryption or deep inspection policy—this tool cannot show the path of a specific session through the inspection chain. Running it may even restart or test the IPS engine, potentially disrupting the very traffic you are trying to observe.

  • ✓

    diagnose debug flow filter dport 443 ; diagnose debug flow show function-name ; diagnose debug enable

    Why this is correct

    This sequence enables real-time flow debugging filtered to destination port 443, with function-name output to display each FortiOS inspection stage (e.g., SSL proxy, application control, IPS). The 'diagnose debug enable' command activates the trace, streaming event details to the console as the packet traverses the engine. It is the most direct way to pinpoint exactly where an HTTPS session is accepted, decrypted, blocked, or dropped.

  • ✗

    diagnose sys session filter dport 443 ; diagnose sys session list

    Why it's wrong here

    This command lists existing sessions from the conntrack session table after filtering for port 443, providing a static snapshot rather than a live trace. It shows the 5-tuple and current state (e.g., established, UDP, or TCP) but omits the internal function calls and proxy stages that determine whether HTTPS inspection is applied. A session can exist in the table yet still bypass deep inspection, so this tool cannot reveal why the inspection is failing.

  • ✗

    execute log display

    Why it's wrong here

    This command retrieves logs from FortiOS memory or disk, which are written after events occur and often lack the granular, per-function tracing needed to see live HTTPS inspection decisions. Unlike the debug flow output, it does not follow a packet in real time, and the administrator must manually correlate log entries with the exact session. The logs may also be rotated or filtered by severity, making them unreliable for diagnosing a transient inspection failure.

  • ✓

    diagnose sniffer packet any 'port 443' 4

    Why this is correct

    This command captures raw packets on the wire for TCP/UDP port 443, allowing the administrator to observe the TLS handshake and whether the FortiGate is physically seeing the HTTPS traffic. It is a valid debugging tool because it can confirm connectivity to the server, detect packet loss, and show if the client is trying to establish a TLS session. However, it operates below the inspection engine, so it cannot show the decrypted content or the internal function stages that flow debug reveals.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.