Courseiva

NSE4 High Availability and Diagnostics Practice Question

An administrator wants to view the current session table entries filtered by destination port 443. Which command should be used?

⚠ Common exam trap

NSE4 often tests whether candidates confuse 'diagnose sys session filter/list' (session table inspection) with 'diagnose debug flow filter' (real-time packet debugging), leading them to pick the debug flow command.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose sys session filter dport 443; diagnose sys session list

FortiGate session table inspection uses the 'diagnose sys session filter' command to set filter criteria (such as dport 443), followed by 'diagnose sys session list' to display matching entries. This two-step filter-then-list pattern is the correct syntax.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    diagnose sys session filter dport 443; diagnose sys session list

    Why this is correct

    The correct workflow in FortiOS for inspecting the session table is to first set a filter with 'diagnose sys session filter dport 443', which configures the current CLI session to show only sessions with a destination port of 443. Then 'diagnose sys session list' prints the matching entries from the kernel session table. This two-step approach lets you combine multiple filter criteria without passing them as command arguments.

  • ✗

    execute session list dport 443

    Why it's wrong here

    The 'execute' command hierarchy contains operational commands such as 'ping' or 'reboot', not diagnostic output commands. 'execute session list' is not a valid FortiOS command, and even if it existed, it would not be the correct way to inspect the session table. Session inspection always requires the 'diagnose sys session' prefix, so this option fails on both validity and intent.

  • ✗

    diagnose debug flow filter dport 443

    Why it's wrong here

    'diagnose debug flow' is a packet‑tracing utility that shows how specific packets traverse the FortiGate, which is useful for verifying the forwarding path, not for browsing the existing session table. The 'filter' here applies to the packet trace (e.g., matching a packet's destination port) rather than to the session table. To list sessions, you must use 'diagnose sys session list' after setting a separate session filter.

  • ✗

    diagnose sys session list dport 443

    Why it's wrong here

    Although 'diagnose sys session list' is the correct command to display sessions, it does not accept inline filter arguments like 'dport 443'. FortiOS requires you to issue 'diagnose sys session filter dport 443' first, and then 'list' uses the filter that was previously set. Passing the port directly to 'list' results in a syntax error or misinterpretation.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator wants to view the current session table on a FortiGate. Which command should they use?

medium
  • A.diagnose debug flow
  • B.show full-configuration
  • ✓ C.diagnose sys session list
  • D.get system performance statistics

Why C: The command 'diagnose sys session list' displays the current session table on a FortiGate, showing active sessions with source/destination, protocol, state, and policy information. It is the standard CLI command for inspecting the session table in real time.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.