Courseiva

NSE4 High Availability and Diagnostics Practice Question

A FortiGate administrator needs to capture packets on the DMZ interface to troubleshoot a connectivity issue. Which CLI command should be used to start a packet capture?

⚠ Common exam trap

NSE4 often tests the correct syntax for packet capture, and candidates may confuse it with debug flow or other diagnose commands.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose sniffer packet

The correct CLI command to start a packet capture on a FortiGate is 'diagnose sniffer packet'. This command allows you to capture packets on a specific interface with various filters and verbosity levels. It is the standard tool for troubleshooting connectivity issues at the packet level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    diagnose sniffer packet

    Why this is correct

    diagnose sniffer packet is the correct FortiGate CLI command for capturing raw packets on an interface. It accepts an interface name (or 'any'), a BPF filter, a count, and a verbosity level, functioning much like tcpdump. This command provides direct visibility into the actual frames on the wire, making it the go-to tool for packet-level troubleshooting.

  • ✗

    diagnose debug flow

    Why it's wrong here

    diagnose debug flow is used to trace the internal packet processing path through the FortiGate, showing how a packet is handled by policy lookup, NAT, routing, and session setup. It outputs debug logs about the session lifecycle, not the raw packet contents. This command helps understand why a session is allowed or denied, but it cannot show the payload or header details at the wire level.

  • ✗

    diagnose sys session list

    Why it's wrong here

    diagnose sys session list displays the current session table entries, including source/destination IP addresses, ports, and session states. It is a snapshot of active sessions passing through the firewall, similar to 'show session' on other firewalls. This command does not capture or inspect packet data; it only summarizes the existing connections, making it unsuitable for packet capture.

  • ✗

    execute packet-capture start

    Why it's wrong here

    execute packet-capture start is not a valid FortiGate CLI command. The 'execute' branch is reserved for operational commands such as 'execute ping' or 'execute reboot', but packet capture is not one of them. The correct syntax for packet capture on FortiGate is always 'diagnose sniffer packet', so this option is fundamentally invalid.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.