Courseiva

NSE4 High Availability and Diagnostics Practice Question

A FortiGate administrator is troubleshooting why traffic from a specific source IP is not being logged. The traffic is allowed by a firewall policy with logging enabled. Which TWO commands could the administrator use to verify if the traffic is hitting the expected policy? (Choose two.)

⚠ Common exam trap

NSE4 often tests the difference between packet capture (sniffer) and policy-lookup tracing (debug flow), causing candidates to choose sniffer when the question asks which policy the traffic hits.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose debug flow

Option B (diagnose debug flow) is correct because it traces a packet through the FortiGate's inspection path, showing which firewall policy matches the traffic and whether it is allowed or denied, which directly verifies if the source IP hits the expected policy. Option D (diagnose sys session filter src 10.0.0.1) is correct because it filters the session table by the source IP so the administrator can run 'diagnose sys session list' and confirm the session was created and which policy ID it matched. Option A (get system performance status) only shows CPU, memory, and uptime statistics and provides no policy-matching information. Option C (diagnose sniffer packet any 'host 10.0.0.1') captures raw packets but does not reveal which firewall policy processed them. Option E (diagnose debug application fnbamd) debugs the Fortinet non-blocking authentication daemon, which is unrelated to firewall policy matching for this traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    get system performance status

    Why it's wrong here

    The 'get system performance status' command provides a snapshot of the FortiGate's resource usage, such as CPU, memory, and session table capacity. It shows whether the device is running out of resources, but it gives no visibility into packet flow or the specific firewall policy that a particular traffic session matched. For policy-matching diagnostics, you need a tool that traces the packet through the firewall pipeline, not a system-wide health check.

  • ✓

    diagnose debug flow

    Why this is correct

    The 'diagnose debug flow' command is the definitive real-time tracing tool for FortiGate traffic. It allows you to apply filters (e.g., by source IP, destination IP, port, or VLAN) and then traces each packet through the entire data path, showing the exact policy ID matched, the action taken (accept or drop), and any profile-based processing or session errors. This output directly answers the question of 'which policy did this traffic match?' making it the correct troubleshooting method.

  • ✗

    diagnose sniffer packet any 'host 10.0.0.1'

    Why it's wrong here

    The 'diagnose sniffer packet any "host 10.0.0.1"' command captures raw packets as they appear on the network interfaces, showing headers, payloads, and timestamps. While useful for confirming that packets are actually arriving at or leaving the FortiGate, it does not reveal the internal firewall policy decision, because policy lookup occurs in the stateful inspection engine, not on the wire. A packet capture alone cannot show which policy ID was matched; you need a flow trace or session table dump for that.

  • ✓

    diagnose sys session filter src 10.0.0.1

    Why this is correct

    The 'diagnose sys session filter src 10.0.0.1' command restricts the session table to only entries with a source IP of 10.0.0.1. When followed by 'diagnose sys session list', it displays existing sessions and each includes the policy ID that the session matched, which is useful for verifying the policy applied to already-established connections. However, it only shows current sessions and does not trace live packets or explain why a new connection is being dropped. It is a complementary view, but not the primary tool for real-time policy matching.

  • ✗

    diagnose debug application fnbamd

    Why it's wrong here

    The 'diagnose debug application fnbamd' command enables debug logging for the FNBAMD daemon, which handles authentication functions such as firewall user authentication, RADIUS, LDAP, and FSSO. Debugging this daemon shows authentication-related events and errors, not the firewall policy lookup or traffic flow. If the issue is unrelated to user authentication, this command will produce irrelevant output and will not help identify which policy matched or dropped a traffic flow.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A FortiGate administrator is troubleshooting a traffic issue where users cannot access a specific website. The administrator runs 'diagnose debug flow' and sees the output indicating that traffic is being denied by a firewall policy. Which two actions should the administrator take to identify the specific policy denying the traffic? (Choose two.)

medium
  • A.Run 'diagnose debug enable' and then reproduce the issue
  • B.Use 'diagnose sys session list' to find the policy ID
  • ✓ C.Review the policy list and look for the policy ID shown in the debug output
  • ✓ D.Check the traffic log for the session to see the policy ID
  • E.Disable all firewall policies temporarily

Why C: Option C is correct because the 'diagnose debug flow' output explicitly prints the policy ID (e.g., 'matched policy 5') that denied the traffic, so reviewing the firewall policy list for that ID pinpoints the exact offending policy. Option D is correct because FortiGate traffic logs record the policy ID (policyid) for each session, so checking the log entry for the denied session reveals the same policy identifier and confirms which rule blocked the traffic. Option A is not the right action because 'diagnose debug enable' only turns on debug output; it does not itself identify the policy, and the administrator has already captured the flow output. Option B is incorrect because 'diagnose sys session list' shows session details such as source/destination and state, but it does not reliably surface the denying policy ID for a denied flow. Option E is incorrect and dangerous because disabling all firewall policies would remove security enforcement and is not a valid troubleshooting step.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.