NSE4 High Availability and Diagnostics Practice Question
An administrator wants to monitor real-time traffic flows on a FortiGate, specifically to see packet details for traffic matching certain criteria. Which command should the administrator use to capture live packets on an interface?
⚠ Common exam trap
NSE4 often tests the distinction between 'diagnose sniffer packet' (raw packet capture) and 'diagnose debug flow' (session/flow tracing) — candidates confuse the two because both are used for traffic troubleshooting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose sniffer packet
The 'diagnose sniffer packet' command is FortiGate's built-in packet capture tool, allowing administrators to capture live packets on a specified interface with optional filters for host, port, and protocol. It provides real-time packet-level visibility similar to tcpdump, which is exactly what is needed to inspect packet details for traffic matching specific criteria.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
diagnose sniffer packet
Why this is correct
diagnose sniffer packet is the correct command for real-time packet-level monitoring. It instructs the FortiGate's kernel to capture raw packets on a specified interface (or 'any') and displays their headers and payload directly in the terminal, optionally filtered by protocol, host, or port. This is equivalent to tcpdump on Linux and is the go-to tool when you need to see the actual bytes crossing the wire, not just session summaries.
- ✗
diagnose debug enable and diagnose debug flow trace
Why it's wrong here
The combination of diagnose debug enable and diagnose debug flow trace enables the session debug flow engine, which prints state-transition messages for the FortiOS session table, such as how a packet is matched to a session and why it was forwarded or dropped. While useful for troubleshooting session setup and policy issues, it does not capture or display the raw packet contents or real-time traffic; it only shows logged events about those sessions. Thus, it cannot serve as a packet sniffer.
- ✗
diagnose sys session list
Why it's wrong here
diagnose sys session list dumps the current session table, showing one line per active session with the 5-tuple (source/destination IP, ports, protocol) and session state information. It provides a static point-in-time inventory of sessions, not a dynamic view of packets as they traverse the device, and it never displays payload data. Therefore, it cannot show real-time traffic flow or packet-level details.
- ✗
execute system grep from CLI
Why it's wrong here
execute system grep is a FortiGate CLI utility for searching text in output from other commands or in system logs; it is not a traffic-capture mechanism. It has no ability to tap an interface, read packets, or monitor network flows in real time, and attempting to use it for that purpose will simply return no matching data or an error. This option is entirely unrelated to packet monitoring.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.