NSE4 High Availability and Diagnostics Practice Question
An administrator wants to view real-time debug output for traffic flowing through a FortiGate. Which command should they use to enable flow tracing with a specific source IP filter?
⚠ Common exam trap
The trap is confusing session filters with debug flow filters; candidates might choose 'diagnose sys session filter src' thinking it filters debug output, but it only filters the session table.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose debug flow filter src
The command 'diagnose debug flow filter src <IP>' sets a filter to capture debug flow output for a specific source IP. This is the correct first step to enable flow tracing with a source IP filter. After setting the filter, the administrator would run 'diagnose debug enable' to start the debug output. The filter command itself is necessary to narrow down the traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
diagnose debug enable
Why it's wrong here
The 'diagnose debug enable' command is a master switch that activates whichever debug module and filter are already configured, but it does not itself define any debug category, level, or traffic filter. When used without a preceding 'diagnose debug flow filter' command, it will not produce real-time flow output; instead it may generate no flow-related messages or only output from unrelated debug modules that happen to be enabled. In FortiOS, you must first specify the debug type and filter (e.g., 'diagnose debug flow filter src' and 'diagnose debug flow show console enable') before running 'diagnose debug enable' to see targeted, real-time flow traces.
- ✓
diagnose debug flow filter src
Why this is correct
The 'diagnose debug flow filter src' command sets a source IP address filter that restricts the real-time flow debugging output to traffic originating from that specific host. This is the correct first step when you want to trace a particular user's or device's session flow through the FortiGate, because it prevents the console from being flooded with all traffic and makes the output meaningful. After setting this source filter, you must also run 'diagnose debug flow show console enable' and then 'diagnose debug enable' to see the live flow trace messages on the CLI.
- ✗
diagnose sys session filter src
Why it's wrong here
The 'diagnose sys session filter src' command is used to filter the output of 'diagnose sys session list', which displays the current session table contents, not real-time flow-tracing events. It does not attach to the kernel's flow debug hook, so it cannot show the step-by-step processing (e.g., NAT, routing, policy lookup) as packets traverse the FortiGate. Even with the filter set, running 'diagnose debug enable' will not produce any flow trace messages because this command only narrows which existing sessions appear in session listing commands, not live debug output.
- ✗
diagnose sniffer packet filter src
Why it's wrong here
The 'diagnose sniffer packet filter src' command configures a packet capture filter for the built-in sniffer, which dumps raw Ethernet/IP packets seen on an interface. Packet sniffing is a low-level network troubleshooting tool that shows the actual packet contents and headers, but it does not provide the session-level flow trace information that 'diagnose debug flow' offers, such as FortiGate's internal processing decisions, session setup/teardown, and NAT translations. For real-time debug output of traffic flows (not raw packets), the correct command is 'diagnose debug flow filter src', making the sniffer command an incorrect choice for this task.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A FortiGate administrator wants to see real-time debugging output for traffic matching a specific source IP address. Which command sequence would achieve this?
easy- A.diagnose sys session filter src 10.0.1.10 ; diagnose sys session list
- ✓ B.diagnose debug flow filter src 10.0.1.10 ; diagnose debug flow show function-name ; diagnose debug enable
- C.diagnose sniffer packet any 'host 10.0.1.10' 4
- D.diagnose debug reset ; diagnose debug enable ; diagnose debug flow show iprope
Why B: The 'diagnose debug flow' command sequence is specifically designed for real-time debugging of traffic flows, allowing filtering by source IP with the 'filter src' option. Enabling debug output with 'diagnose debug enable' then shows flow trace information for packets matching the filter, which is the standard method for live traffic debugging on FortiGate.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.