NSE4 High Availability and Diagnostics Practice Question
A FortiGate administrator wants to see real-time debugging output for traffic matching a specific source IP address. Which command sequence would achieve this?
⚠ Common exam trap
Many candidates confuse packet sniffing (Option C) with flow debugging (Option B), as both can show traffic for a specific IP, but only debug flow reveals the firewall's internal processing decisions (e.g., policy ID, NAT action) in real time, which is essential for diagnosing policy-related issues.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose debug flow filter src 10.0.1.10 ; diagnose debug flow show function-name ; diagnose debug enable
The 'diagnose debug flow' command sequence is specifically designed for real-time debugging of traffic flows, allowing filtering by source IP with the 'filter src' option. Enabling debug output with 'diagnose debug enable' then shows flow trace information for packets matching the filter, which is the standard method for live traffic debugging on FortiGate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
diagnose sys session filter src 10.0.1.10 ; diagnose sys session list
Why it's wrong here
The command pair `diagnose sys session filter src 10.0.1.10 ; diagnose sys session list` queries the session table and prints a point-in-time snapshot of active sessions that match the source IP filter. It does not provide real-time tracing of packet processing through the kernel, nor does it show debug messages as packets traverse firewall policies, session creation, or routing lookups. The `diagnose sys session` utility is for inspecting established session entries, not for streaming per-packet debug flow events, so it cannot reveal transient drops or policy decisions.
- ✓
diagnose debug flow filter src 10.0.1.10 ; diagnose debug flow show function-name ; diagnose debug enable
Why this is correct
This correct sequence first installs a flow trace filter for the source IP, then selects the `function-name` output mode to display the names of kernel functions that process the matching packets, and finally enables debug output. The order is critical because the filter must be active before debugging starts to avoid capturing unrelated traffic, and the `show` option must be set before `enable` takes effect. Once enabled, the FortiGate outputs a step-by-step traversal of the packet through the firewall, including policy lookups, session setup, and any drops, which is exactly what real-time debugging requires.
- ✗
diagnose sniffer packet any 'host 10.0.1.10' 4
Why it's wrong here
The command `diagnose sniffer packet any 'host 10.0.1.10' 4` runs a packet sniffer on all interfaces with a host filter and a verbosity level of 4 (typically full header and payload display). While it captures raw frames in real time and can show the packet contents, it operates at a different layer: it shows the actual packets on the wire but does not expose the internal software path or the firewall's decision-making process. The sniffer cannot show which policy matched, whether a session was denied, or why a packet was dropped, so it is unsuitable for flow debugging compared to `diagnose debug flow`.
- ✗
diagnose debug reset ; diagnose debug enable ; diagnose debug flow show iprope
Why it's wrong here
This attempt is invalid because the debug enable is executed before the flow filter and output options are configured, so the debugger would start with default settings and no source IP filter, generating a flood of output for all flows. Additionally, `diagnose debug flow show iprope` is placed after `diagnose debug enable`, meaning the output format selection is ineffective; in the proper sequence, filter and show commands must precede `diagnose debug enable`. The `diagnose debug reset` only clears previous settings and does not set a filter, and the absence of a `filter` command means the administrator cannot narrow the trace to the host 10.0.1.10, making the output unmanageable and incomplete.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.