Courseiva

NSE4 High Availability and Diagnostics Practice Question

An administrator wants to view the current session table on a FortiGate. Which command should they use?

⚠ Common exam trap

NSE4 often tests the confusion between 'diagnose debug flow' (packet tracing) and 'diagnose sys session list' (session table inspection), since both are used in troubleshooting but serve different purposes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose sys session list

The command 'diagnose sys session list' displays the current session table on a FortiGate, showing active sessions with source/destination, protocol, state, and policy information. It is the standard CLI command for inspecting the session table in real time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    diagnose debug flow

    Why it's wrong here

    The 'diagnose debug flow' command is a real-time packet tracer that prints a log entry for every packet as it traverses the FortiGate's forwarding path. It does not enumerate or list the existing session table; instead, it requires live traffic to generate output and shows per-packet events such as checksum validation, route lookup, and policy hits. For inspecting already-established sessions, you must use 'diagnose sys session list'.

  • ✗

    show full-configuration

    Why it's wrong here

    'show full-configuration' dumps the entire static configuration of the FortiGate, including interfaces, policies, routing, DHCP, and other settings stored in the system's config database. Session table entries are dynamically created in kernel memory when traffic matches a policy and are never saved to the configuration file. Therefore this command is completely blind to the runtime state of active sessions.

  • ✓

    diagnose sys session list

    Why this is correct

    'diagnose sys session list' is the correct command to view the current session table. It reads the kernel session table and outputs every active connection, including source/destination IP addresses, ports, protocol, session state, and timers. This is the standard tool for troubleshooting NAT, policy, and asymmetric routing because it shows exactly what the firewall is tracking in real time.

  • ✗

    get system performance statistics

    Why it's wrong here

    'get system performance statistics' reports aggregate system-level metrics such as CPU usage, memory utilization, packet throughput, and interface counters. It does not drill down into individual session details like IP addresses or ports, so you cannot use it to view the session table. This command is useful for monitoring overall system health, not for inspecting connection-level state.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.