Courseiva

NSE4 High Availability and Diagnostics Practice Question

An administrator wants to monitor real-time traffic flows on a FortiGate, specifically to see packet details for traffic matching certain criteria. Which command should the administrator use to capture live packets on an interface?

⚠ Common exam trap

NSE4 often tests the distinction between 'diagnose sniffer packet' (raw packet capture) and 'diagnose debug flow' (session/flow tracing) — candidates confuse the two because both are used for traffic troubleshooting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose sniffer packet

The 'diagnose sniffer packet' command is FortiGate's built-in packet capture tool, allowing administrators to capture live packets on a specified interface with optional filters for host, port, and protocol. It provides real-time packet-level visibility similar to tcpdump, which is exactly what is needed to inspect packet details for traffic matching specific criteria.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    diagnose sniffer packet

    Why this is correct

    diagnose sniffer packet is the correct command for real-time packet-level monitoring. It instructs the FortiGate's kernel to capture raw packets on a specified interface (or 'any') and displays their headers and payload directly in the terminal, optionally filtered by protocol, host, or port. This is equivalent to tcpdump on Linux and is the go-to tool when you need to see the actual bytes crossing the wire, not just session summaries.

  • ✗

    diagnose debug enable and diagnose debug flow trace

    Why it's wrong here

    The combination of diagnose debug enable and diagnose debug flow trace enables the session debug flow engine, which prints state-transition messages for the FortiOS session table, such as how a packet is matched to a session and why it was forwarded or dropped. While useful for troubleshooting session setup and policy issues, it does not capture or display the raw packet contents or real-time traffic; it only shows logged events about those sessions. Thus, it cannot serve as a packet sniffer.

  • ✗

    diagnose sys session list

    Why it's wrong here

    diagnose sys session list dumps the current session table, showing one line per active session with the 5-tuple (source/destination IP, ports, protocol) and session state information. It provides a static point-in-time inventory of sessions, not a dynamic view of packets as they traverse the device, and it never displays payload data. Therefore, it cannot show real-time traffic flow or packet-level details.

  • ✗

    execute system grep from CLI

    Why it's wrong here

    execute system grep is a FortiGate CLI utility for searching text in output from other commands or in system logs; it is not a traffic-capture mechanism. It has no ability to tap an interface, read packets, or monitor network flows in real time, and attempting to use it for that purpose will simply return no matching data or an error. This option is entirely unrelated to packet monitoring.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.