NSE4 High Availability and Diagnostics Practice Question
A FortiGate administrator needs to capture packets on the DMZ interface to troubleshoot a connectivity issue. Which CLI command should be used to start a packet capture?
⚠ Common exam trap
NSE4 often tests the correct syntax for packet capture, and candidates may confuse it with debug flow or other diagnose commands.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose sniffer packet
The correct CLI command to start a packet capture on a FortiGate is 'diagnose sniffer packet'. This command allows you to capture packets on a specific interface with various filters and verbosity levels. It is the standard tool for troubleshooting connectivity issues at the packet level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
diagnose sniffer packet
Why this is correct
diagnose sniffer packet is the correct FortiGate CLI command for capturing raw packets on an interface. It accepts an interface name (or 'any'), a BPF filter, a count, and a verbosity level, functioning much like tcpdump. This command provides direct visibility into the actual frames on the wire, making it the go-to tool for packet-level troubleshooting.
- ✗
diagnose debug flow
Why it's wrong here
diagnose debug flow is used to trace the internal packet processing path through the FortiGate, showing how a packet is handled by policy lookup, NAT, routing, and session setup. It outputs debug logs about the session lifecycle, not the raw packet contents. This command helps understand why a session is allowed or denied, but it cannot show the payload or header details at the wire level.
- ✗
diagnose sys session list
Why it's wrong here
diagnose sys session list displays the current session table entries, including source/destination IP addresses, ports, and session states. It is a snapshot of active sessions passing through the firewall, similar to 'show session' on other firewalls. This command does not capture or inspect packet data; it only summarizes the existing connections, making it unsuitable for packet capture.
- ✗
execute packet-capture start
Why it's wrong here
execute packet-capture start is not a valid FortiGate CLI command. The 'execute' branch is reserved for operational commands such as 'execute ping' or 'execute reboot', but packet capture is not one of them. The correct syntax for packet capture on FortiGate is always 'diagnose sniffer packet', so this option is fundamentally invalid.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.