NSE4 High Availability and Diagnostics Practice Question
A FortiGate administrator is troubleshooting why traffic from a specific source IP is not being logged. The traffic is allowed by a firewall policy with logging enabled. Which TWO commands could the administrator use to verify if the traffic is hitting the expected policy? (Choose two.)
⚠ Common exam trap
NSE4 often tests the difference between packet capture (sniffer) and policy-lookup tracing (debug flow), causing candidates to choose sniffer when the question asks which policy the traffic hits.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose debug flow
Option B (diagnose debug flow) is correct because it traces a packet through the FortiGate's inspection path, showing which firewall policy matches the traffic and whether it is allowed or denied, which directly verifies if the source IP hits the expected policy. Option D (diagnose sys session filter src 10.0.0.1) is correct because it filters the session table by the source IP so the administrator can run 'diagnose sys session list' and confirm the session was created and which policy ID it matched. Option A (get system performance status) only shows CPU, memory, and uptime statistics and provides no policy-matching information. Option C (diagnose sniffer packet any 'host 10.0.0.1') captures raw packets but does not reveal which firewall policy processed them. Option E (diagnose debug application fnbamd) debugs the Fortinet non-blocking authentication daemon, which is unrelated to firewall policy matching for this traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
get system performance status
Why it's wrong here
The 'get system performance status' command provides a snapshot of the FortiGate's resource usage, such as CPU, memory, and session table capacity. It shows whether the device is running out of resources, but it gives no visibility into packet flow or the specific firewall policy that a particular traffic session matched. For policy-matching diagnostics, you need a tool that traces the packet through the firewall pipeline, not a system-wide health check.
- ✓
diagnose debug flow
Why this is correct
The 'diagnose debug flow' command is the definitive real-time tracing tool for FortiGate traffic. It allows you to apply filters (e.g., by source IP, destination IP, port, or VLAN) and then traces each packet through the entire data path, showing the exact policy ID matched, the action taken (accept or drop), and any profile-based processing or session errors. This output directly answers the question of 'which policy did this traffic match?' making it the correct troubleshooting method.
- ✗
diagnose sniffer packet any 'host 10.0.0.1'
Why it's wrong here
The 'diagnose sniffer packet any "host 10.0.0.1"' command captures raw packets as they appear on the network interfaces, showing headers, payloads, and timestamps. While useful for confirming that packets are actually arriving at or leaving the FortiGate, it does not reveal the internal firewall policy decision, because policy lookup occurs in the stateful inspection engine, not on the wire. A packet capture alone cannot show which policy ID was matched; you need a flow trace or session table dump for that.
- ✓
diagnose sys session filter src 10.0.0.1
Why this is correct
The 'diagnose sys session filter src 10.0.0.1' command restricts the session table to only entries with a source IP of 10.0.0.1. When followed by 'diagnose sys session list', it displays existing sessions and each includes the policy ID that the session matched, which is useful for verifying the policy applied to already-established connections. However, it only shows current sessions and does not trace live packets or explain why a new connection is being dropped. It is a complementary view, but not the primary tool for real-time policy matching.
- ✗
diagnose debug application fnbamd
Why it's wrong here
The 'diagnose debug application fnbamd' command enables debug logging for the FNBAMD daemon, which handles authentication functions such as firewall user authentication, RADIUS, LDAP, and FSSO. Debugging this daemon shows authentication-related events and errors, not the firewall policy lookup or traffic flow. If the issue is unrelated to user authentication, this command will produce irrelevant output and will not help identify which policy matched or dropped a traffic flow.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A FortiGate administrator is troubleshooting a traffic issue where users cannot access a specific website. The administrator runs 'diagnose debug flow' and sees the output indicating that traffic is being denied by a firewall policy. Which two actions should the administrator take to identify the specific policy denying the traffic? (Choose two.)
medium- A.Run 'diagnose debug enable' and then reproduce the issue
- B.Use 'diagnose sys session list' to find the policy ID
- ✓ C.Review the policy list and look for the policy ID shown in the debug output
- ✓ D.Check the traffic log for the session to see the policy ID
- E.Disable all firewall policies temporarily
Why C: Option C is correct because the 'diagnose debug flow' output explicitly prints the policy ID (e.g., 'matched policy 5') that denied the traffic, so reviewing the firewall policy list for that ID pinpoints the exact offending policy. Option D is correct because FortiGate traffic logs record the policy ID (policyid) for each session, so checking the log entry for the denied session reveals the same policy identifier and confirms which rule blocked the traffic. Option A is not the right action because 'diagnose debug enable' only turns on debug output; it does not itself identify the policy, and the administrator has already captured the flow output. Option B is incorrect because 'diagnose sys session list' shows session details such as source/destination and state, but it does not reliably surface the denying policy ID for a denied flow. Option E is incorrect and dangerous because disabling all firewall policies would remove security enforcement and is not a valid troubleshooting step.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.