Courseiva

CCNA Nse4 Ha Diagnostics Questions

26 of 101 questions · Page 2/2 · Nse4 Ha Diagnostics topic · Answers revealed

76
MCQeasy

An administrator wants to view real-time debug output for traffic flowing through a FortiGate. Which command should they use to enable flow tracing with a specific source IP filter?

A.diagnose debug enable
B.diagnose debug flow filter src
C.diagnose sys session filter src
D.diagnose sniffer packet filter src
AnswerB

The 'diagnose debug flow filter src' command sets a source IP address filter that restricts the real-time flow debugging output to traffic originating from that specific host. This is the correct first step when you want to trace a particular user's or device's session flow through the FortiGate, because it prevents the console from being flooded with all traffic and makes the output meaningful. After setting this source filter, you must also run 'diagnose debug flow show console enable' and then 'diagnose debug enable' to see the live flow trace messages on the CLI.

Why this answer

The command 'diagnose debug flow filter src <IP>' sets a filter to capture debug flow output for a specific source IP. This is the correct first step to enable flow tracing with a source IP filter. After setting the filter, the administrator would run 'diagnose debug enable' to start the debug output.

The filter command itself is necessary to narrow down the traffic.

Exam trap

The trap is confusing session filters with debug flow filters; candidates might choose 'diagnose sys session filter src' thinking it filters debug output, but it only filters the session table.

How to eliminate wrong answers

Option A is wrong because 'diagnose debug enable' only enables debug output but does not set a filter; without a filter, the output would be overwhelming. Option C is wrong because 'diagnose sys session filter src' filters the session table, not debug flow output. Option D is wrong because 'diagnose sniffer packet filter src' is not a valid command; the sniffer uses different syntax and is for packet capture, not debug flow.

77
MCQhard

An administrator is troubleshooting a slow web application. The admin suspects that the FortiGate's session table might be full, causing new sessions to be dropped. Which command should the admin use to check the current session table utilization?

A.get system performance status
B.diagnose sys session list
C.diagnose sys session stat
D.diagnose sys session filter
AnswerC

The 'diagnose sys session stat' command is the correct choice because it directly reports session table statistics, including the current number of sessions, the configured maximum, and the utilization percentage. These metrics allow the administrator to quickly determine whether the FortiGate is approaching its session limit, which can cause new connection failures and slow performance for web applications. This command is purpose-built for assessing session-table pressure and is the most efficient way to diagnose session exhaustion.

Why this answer

The command 'diagnose sys session stat' provides a summary of session table statistics, including the current session count, maximum session count, and utilization percentage. This directly answers whether the session table is full. It is the correct command to quickly assess session table utilization without listing every session.

Exam trap

NSE4 often tests the difference between commands that list sessions versus those that provide summary statistics, causing candidates to choose 'diagnose sys session list' when a quick utilization check is needed.

How to eliminate wrong answers

Option A is wrong because 'get system performance status' displays overall system performance metrics like CPU, memory, and network usage, not session table utilization. Option B is wrong because 'diagnose sys session list' lists all current sessions, which is verbose and does not provide a summary of utilization; it is useful for detailed inspection but not for quick utilization check. Option D is wrong because 'diagnose sys session filter' is used to set filters for session listing, not to display statistics.

78
MCQmedium

A FortiGate HA cluster is operating in active-passive mode. The active unit fails over to the passive unit. After the failover, some existing TCP sessions are dropped. What is the MOST likely cause?

A.The HA heartbeat interface has a high latency
B.The failover time is too slow, causing TCP timeouts
C.Session synchronization is not enabled or not working properly
D.The TCP sessions are using NAT, which cannot be synchronized
AnswerC

In active-passive HA, the standby unit does not have the active unit's session table unless session pickup (session synchronization) is enabled and functioning. When a failover occurs, the newly active unit has no knowledge of the established TCP connections, so it cannot forward packets for those flows and they must be re-established. If session sync is enabled but not working, the same result occurs, so the correct fix is to verify that the session pickup feature is properly configured and that heartbeat interface is carrying the synchronization updates.

Why this answer

In an active-passive FortiGate HA cluster, the passive unit only maintains existing TCP sessions if session synchronization (session-pickup) is enabled and functioning. When the active unit fails, the passive unit becomes active and must have the session state to continue forwarding packets for established connections. If session synchronization is not enabled or is broken (e.g., due to a misconfigured sync interface or high latency), the new active unit has no knowledge of existing sessions and drops them, forcing clients to re-establish connections.

Thus, the most likely cause is that session synchronization is not enabled or not working properly.

Exam trap

NSE4 often tests the misconception that NAT prevents session synchronization or that failover speed alone determines session continuity, when in fact session synchronization must be explicitly enabled and operational for existing sessions to survive a failover.

How to eliminate wrong answers

Option A is wrong because high latency on the HA heartbeat interface typically causes heartbeat timeouts and unnecessary failovers, but it does not directly cause existing TCP sessions to be dropped after a failover; session synchronization is the key factor. Option B is wrong because failover time being too slow would cause TCP timeouts only if the failover exceeds the TCP retransmission timeout, but FortiGate HA failover is usually fast (sub-second to a few seconds), and the question implies the failover occurred; the more direct cause is lack of session sync. Option D is wrong because NAT sessions can be synchronized in FortiGate HA; NAT does not prevent session synchronization, and claiming it cannot be synchronized is a misconception.

79
MCQeasy

Which FortiGuard subscription service is required for URL filtering and web categorization?

A.FortiGuard IPS
B.FortiGuard Application Control
C.FortiGuard Web Filtering
D.FortiGuard Antivirus
AnswerC

FortiGuard Web Filtering is the subscription service that provides comprehensive URL categorization and filtering, using a cloud-based database to classify websites into categories such as malware, Phishing, or gambling. This service enables FortiGate to enforce web access policies by comparing requested URLs against category and reputation data in real time. Without this subscription, URL filtering is unavailable, so it is the correct choice for this requirement.

Why this answer

FortiGuard Web Filtering provides URL categorization and filtering capabilities.

80
Matchingmedium

Match each FortiGate routing concept to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Manually configured path to a destination network

Link-state routing protocol for internal networks

Path-vector routing protocol for internet and WAN

Routes traffic based on source/destination or service

Load-balances traffic across multiple routes with same cost

Why these pairings

In FortiGate, static routing relies on manual configuration, while dynamic routing uses protocols like OSPF and BGP. Policy-based routing forwards based on packet characteristics, and ECMP load-balances over equal-cost paths. Common confusions involve swapping the definitions of static and dynamic routing, or confusing dynamic routing with policy-based routing.

81
MCQmedium

An administrator notices that traffic matching a firewall policy is not being logged. The policy has logging enabled. The FortiGate has local disk storage. What should the administrator check first?

A.Whether the FortiGate has a valid FortiAnalyzer subscription
B.Whether FortiCloud logging is enabled
C.The disk health and available space using 'diagnose sys disk' commands
D.The log severity level on the policy
AnswerC

When local logs are missing, the first step is to verify the storage subsystem with 'diagnose sys disk' to inspect disk health, mount status, and available space. A full or failing disk, or an exhausted inode table, can cause log writes to fail silently, resulting in no entries in the local log view. This command reveals whether the disk is online, has sufficient free blocks, and has no file-system errors. Only after confirming the disk is healthy should you examine logging filters or remote destinations.

Why this answer

When a FortiGate policy has logging enabled but logs are not appearing, and the device uses local disk storage, the first thing to check is whether the disk is healthy and has available space. FortiOS stops writing logs when the disk is full or failing, and 'diagnose sys disk' commands reveal disk health, usage, and log partition status. This is the most direct and common cause of missing local logs.

Exam trap

NSE4 often tests the assumption that logging issues are always about severity or remote destinations — candidates overlook that local disk health and free space are the first thing to verify when local logging silently stops.

How to eliminate wrong answers

Option A is wrong because a FortiAnalyzer subscription is only required for remote logging to FortiAnalyzer — local disk logging does not depend on it, and the question specifies the FortiGate has local disk storage. Option B is wrong because FortiCloud logging is a separate remote logging destination; enabling or disabling it does not affect local disk logging. Option D is wrong because log severity level on the policy filters which events are logged, but if logging is enabled and the severity is set to a reasonable level, the more likely cause of zero logs is a disk issue — and the question states logging is enabled.

82
MCQeasy

A FortiGate administrator needs to check the current HA status of a cluster to determine which unit is the primary. The administrator has CLI access to both units. Which command should be executed on either unit to display the HA status, including the primary unit's hostname and priority?

A.show system ha
B.get system ha status
C.diagnose sys ha status
D.diagnose sys ha dump
AnswerB

This command displays a concise summary of the HA status, including the primary unit's hostname, priority, and HA uptime. It is the standard command to quickly verify which unit is primary and its attributes. It works on either unit and provides the necessary information directly.

Why this answer

The command 'get system ha status' is the correct choice because it provides a clear summary of the HA status, including the primary unit's hostname and priority. It is the standard command for quickly determining which unit is active and its attributes, making it ideal for this scenario.

Exam trap

The trap here is confusing the configuration command 'show system ha' with the operational status command 'get system ha status'.

83
Multi-Selecteasy

Which TWO of the following are valid methods to view real-time debug output on a FortiGate? (Choose two.)

Select 2 answers
A.diagnose sniffer packet
B.diagnose debug enable
C.diagnose sys session list
D.execute tail log
E.diagnose debug flow
AnswersA, E

diagnose sniffer packet is the Fortinet CLI command that invokes the built-in packet capture engine to display live packets as they traverse the specified interface(s) or VLAN(s). It accepts real-time filters such as 'port 443' or host IPs, and a verbosity level (1-6) controlling header vs. full payload display. Because it immediately streams captured frames to the terminal, it is a legitimate real-time traffic-viewing tool.

Why this answer

Diagnose debug flow and diagnose sniffer packet are real-time debug commands. Execute tail log is not a standard command.

84
Multi-Selectmedium

A FortiGate administrator is investigating a performance issue and suspects that a large number of incomplete TCP connections are consuming session table resources. Which TWO commands would help identify such sessions? (Choose two.)

Select 2 answers
A.diagnose debug flow filter dport 80 ; diagnose debug enable
B.diagnose sys session stat
C.diagnose sniffer packet any 'tcp' 4
D.diagnose sys session filter state syn-sent ; diagnose sys session list
E.diagnose sys session filter proto 6 ; diagnose sys session list
AnswersB, D

`diagnose sys session stat` is the correct first command because it presents a concise summary of session table statistics, including totals for sessions in various states such as TCP SYN-SENT, SYN-RECV, ESTABLISHED, FIN-WAIT, and others. By observing an unusually high count in the SYN-SENT bucket, an administrator can quickly confirm whether incomplete (half-open) connections are accumulating and contributing to the performance problem. This aggregate view is fast, non-intrusive, and gives immediate insight into the session table distribution without listing individual sessions.

Why this answer

Diagnose sys session list with filter can show sessions by state. Diagnose sys session stat shows counts by state. The sniffer shows packets, not session state; debug flow is for tracing specific streams.

85
MCQeasy

An administrator needs to send logs from a FortiGate to a remote FortiAnalyzer for centralized log storage and analysis. Which configuration step is required on the FortiGate?

A.Configure a firewall policy allowing traffic from FortiGate to FortiAnalyzer on port 514
B.Set the FortiAnalyzer as the log destination in Log Settings
C.Create a log forwarding rule to forward all logs to the FortiAnalyzer
D.Install a FortiGate connector on the FortiAnalyzer
AnswerB

Set the FortiAnalyzer as the log destination in Log Settings. Under System > Log Settings (or via CLI 'config log fortianalyzer setting'), the administrator must specify the FortiAnalyzer IP address and enable log transmission. This action directs the FortiGate to send logs using the native FortiAnalyzer protocol, which provides reliable, acknowledged log delivery. Without this configuration, logs will never leave the FortiGate, regardless of any firewall policies or forwarding rules.

Why this answer

To send logs to FortiAnalyzer, the administrator must configure the FortiAnalyzer as a remote log destination under Log Settings. This is done via 'config log fortianalyzer setting' and specifying the server IP and other parameters.

86
MCQhard

An administrator executes 'diagnose debug flow' for a specific session and sees the output: 'id=20085 trace_id=10 func=print_pkt_detail line=5567 msg="vd-root:0 received packet via port1".' Later, the trace shows 'msg="Deny by policy"'. What is the most likely next step the administrator should take?

A.Check the routing table for the destination
B.Review the firewall policies that apply to the traffic and modify as needed
C.Restart the FortiGate to clear session table
D.Enable session helper for the protocol
AnswerB

The debug flow output's 'Deny by policy' verdict means the FortiGate's firewall policy engine evaluated the packet against the configured policy set and explicitly rejected it, typically due to the absence of a matching permit policy, a matching explicit deny policy, or a policy that disallows the tuple (source, destination, service, user, etc.). Because the packet is denied before session creation, the administrator should inspect the policy list with `diagnose firewall policy list` or via the GUI, and either adjust the existing policy's matching criteria/action or create a new permit policy that allows the legitimate traffic. Correctly aligning the policy to the intended traffic flow is the direct and standard fix, avoiding unnecessary service disruption.

Why this answer

The debug flow output shows the packet was received on port1 and then hit 'Deny by policy', meaning a firewall policy explicitly blocked the traffic. The next logical step is to review the firewall policies that match the traffic's source, destination, service, and incoming interface, and adjust them to permit the intended flow.

Exam trap

NSE4 often tests debug flow message interpretation — candidates see 'Deny by policy' and jump to routing or session issues instead of recognizing it as a firewall policy match failure.

How to eliminate wrong answers

Option A is wrong because the trace already shows the packet reached policy evaluation — routing was resolved enough to select a policy, so routing is not the failure point. Option C is wrong because restarting the FortiGate is disruptive and unnecessary; the deny is a policy decision, not a stuck session table. Option D is wrong because session helpers (e.g., for FTP, SIP) affect application-layer inspection and pinhole creation, not the initial policy deny decision.

87
MCQeasy

A FortiGate administrator receives an alert that the FortiGuard antivirus database on the firewall is outdated. Which subscription service must be active to update the antivirus signatures?

A.FortiGuard IPS Service
B.FortiGuard Application Control Service
C.FortiGuard Antivirus Service
D.FortiGuard Web Filtering Service
AnswerC

FortiGuard Antivirus Service is responsible for delivering up-to-date antivirus engines and virus signature files to the FortiGate, enabling scanning of files, email attachments, and web downloads for known malware. When the administrator sees an alert that antivirus signatures are outdated or failed to update, this is the subscription service to verify and troubleshoot. Without this service, the FortiGate cannot reliably block malicious content based on virus definitions. Therefore, it is the correct choice.

Why this answer

The FortiGuard Antivirus Service subscription is the specific entitlement that provides signature updates for the antivirus engine on a FortiGate. Without an active FortiGuard AV subscription, the FortiGate cannot download updated virus definition databases, which is exactly the alert described. Each FortiGuard subscription is licensed and updated independently, so only the AV service covers AV signature refresh.

Exam trap

NSE4 often tests whether candidates can map a specific FortiGuard update (AV, IPS, App Control, Web Filter) to the correct subscription service, since all four are bundled in UTM and candidates assume any active subscription updates everything.

How to eliminate wrong answers

Option A is wrong because the FortiGuard IPS Service delivers intrusion prevention signatures and engine updates, not antivirus definitions. Option B is wrong because the Application Control Service provides application signature databases for identifying and controlling applications, not virus signatures. Option D is wrong because the Web Filtering Service provides URL/category ratings and web filtering databases, which are unrelated to antivirus signature updates.

88
MCQmedium

A FortiGate administrator needs to forward logs to a FortiAnalyzer for centralized management. The FortiAnalyzer is reachable at 10.0.1.100. Which configuration step is required on the FortiGate to send logs to this FortiAnalyzer?

A.Configure a syslog server under Log Setting
B.Add a firewall policy allowing traffic from FortiGate to FortiAnalyzer
C.Configure the FortiAnalyzer in System > FortiAnalyzer
D.Enable logging to FortiCloud instead
AnswerC

This is the correct method because it establishes the native, authenticated FortiAnalyzer connection. Under System > FortiAnalyzer, you specify the FortiAnalyzer IP address, set an access token or serial number, and enable logging; this configures the FortiGate to use FortiAnalyzer's proprietary logging protocol (FAS) with features like log buffering, encryption, and compression. The CLI equivalent, 'config log fortianalyzer setting', offers the same options and is often used in automated deployments. Once configured, the FortiGate begins forwarding all configured log types to FortiAnalyzer for centralized logging, analytics, and reporting.

Why this answer

To send logs to FortiAnalyzer, the administrator must configure the FortiAnalyzer server under System > FortiAnalyzer or via CLI using 'config log fortianalyzer setting set server 10.0.1.100'. The log forwarding policy is not used for FortiAnalyzer.

89
MCQmedium

An administrator is configuring a new FortiGate HA cluster in active-passive mode. The administrator wants to ensure that the primary unit is always the same physical device, even after a reboot or failure, as long as it is operational. Which HA setting should the administrator configure?

A.Set the HA priority to a higher value on the preferred primary unit.
B.Configure the HA group ID to match the unit's serial number.
C.Set the HA mode to active-active.
D.Enable HA override on the preferred primary unit.
AnswerD

Enabling HA override allows a unit with a higher priority to take over as primary when it becomes available, even if another unit is currently primary. This ensures the preferred unit always becomes primary after a reboot or failure, as long as it is operational. Override must be enabled on the unit that should become primary.

Why this answer

To ensure a specific unit always becomes primary when available, the administrator should enable HA override on that unit and set its priority higher than the other unit. Override allows the unit to preempt the current primary after it reboots or recovers from a failure, maintaining a consistent primary device.

Exam trap

The trap here is assuming that setting a higher priority alone is sufficient; without override enabled, the unit will not reclaim the primary role after recovering from a failure.

90
MCQhard

A FortiGate HA cluster is experiencing frequent failovers. The administrator checks the HA event log and sees repeated 'Heartbeat loss' messages. The heartbeat interfaces are connected directly via a crossover cable. What is the MOST likely cause?

A.The session pickup option is enabled
B.The HA uptime monitor is enabled and tracking a failed interface
C.The HA override setting is disabled
D.The heartbeat interface has a duplex mismatch
AnswerD

A duplex mismatch on the heartbeat interface is the classic cause of intermittent heartbeat loss: one side runs at full duplex and the other at half duplex, leading to late collisions, CRC errors, and frame drops that tend to occur in bursts. These dropped frames are exactly what the HA process sees as a missing heartbeat. If the heartbeat timeout is repeatedly exceeded, the cluster concludes the peer is down and triggers a failover; once traffic resumes, another lost burst starts the cycle, producing the observed frequent failovers.

Why this answer

A duplex mismatch on the heartbeat interface causes intermittent link errors and dropped heartbeat packets, leading to repeated 'Heartbeat loss' messages and frequent failovers. Since the interfaces are directly connected via crossover cable, a speed/duplex mismatch is the most likely physical-layer cause.

Exam trap

NSE4 often tests physical-layer causes of HA instability; the trap is overlooking duplex mismatch and instead blaming HA settings like override or session pickup.

How to eliminate wrong answers

Option A is wrong because session pickup affects session synchronization, not heartbeat integrity, and would not cause heartbeat loss. Option B is wrong because HA uptime monitoring tracks interface availability for failover decisions but does not generate heartbeat loss messages on a direct link. Option C is wrong because HA override controls whether a higher-priority unit preempts, not heartbeat communication reliability.

91
MCQmedium

A FortiGate HA cluster is configured in active-passive mode with two units. The primary unit fails. The secondary unit takes over, but some established TCP sessions are dropped. What is the most likely cause?

A.Session synchronization is not enabled
B.The HA failover threshold is set too high
C.The HA mode is active-passive
D.The heartbeat interface is down
AnswerA

Session synchronization is not enabled. In an active-passive HA cluster, the primary FortiGate maintains the complete session table for all inspected traffic. If session synchronization (or session sync) is not configured via the HA settings, the backup unit does not receive real-time updates about existing sessions. Upon failover, the newly active unit has no entries for these flows, so when endpoints continue sending packets, the FortiGate cannot match them to a session and drops them—causing established TCP connections to break and requiring applications to reconnect. This is the direct cause of the session loss observed.

Why this answer

In an active-passive FortiGate HA cluster, the primary unit synchronizes session state (including TCP session tables) to the secondary unit so that upon failover, established sessions can continue without interruption. If session synchronization is not enabled, the secondary unit has no knowledge of existing sessions, so when it takes over, it drops all established TCP sessions because it has no session entries for them. Thus, the most likely cause is that session synchronization is disabled.

Exam trap

NSE4 often tests the misconception that active-passive HA automatically preserves all sessions, when in fact session synchronization must be explicitly enabled and configured correctly.

How to eliminate wrong answers

Option B is wrong because the HA failover threshold (if configured) determines how many heartbeat misses trigger a failover, not whether sessions are preserved; a high threshold might delay failover but does not cause session drops after failover. Option C is wrong because active-passive HA mode itself does not cause session drops; in fact, it is designed to maintain sessions via synchronization. Option D is wrong because if the heartbeat interface is down, the cluster would likely split or failover might not occur correctly, but the scenario states the secondary unit took over, implying heartbeat communication was functional; a down heartbeat interface would not specifically cause established TCP sessions to drop if session synchronization were enabled.

92
MCQmedium

Which type of log records information about firewall policy matches, such as allowed or denied traffic?

A.Security logs
B.Event logs
C.Traffic logs
D.Audit logs
AnswerC

Traffic logs are the correct answer because they are generated when a session is evaluated against a firewall policy and contain the matching policy ID, action (accept or deny), source/destination IP addresses, ports, protocol, and bytes transferred. These logs let administrators verify which policy handled a given connection, monitor traffic volumes per policy, and troubleshoot connectivity issues. They appear under Log & Report > Traffic Log and serve as the foundation for FortiView session monitoring and policy-based reporting.

Why this answer

Traffic logs in FortiGate record information about firewall policy matches, including allowed and denied traffic. They provide details such as source and destination IP addresses, ports, protocols, and the action taken by the firewall policy. This is the primary log type used for analyzing policy enforcement and troubleshooting connectivity issues.

Exam trap

NSE4 often tests the distinction between traffic logs and security logs, causing candidates to confuse policy match logging with security profile logging.

How to eliminate wrong answers

Option A is wrong because security logs in FortiGate typically refer to logs generated by security profiles such as antivirus, IPS, or web filtering, not basic policy matches. Option B is wrong because event logs record system events, administrative actions, and configuration changes, not traffic policy matches. Option D is wrong because audit logs track administrative activities and configuration changes, not traffic flows.

93
MCQmedium

A FortiGate administrator wants to configure Zero Trust Network Access (ZTNA) to secure access to an internal application. What is required on the FortiGate?

A.A FortiClient EMS subscription
B.A VPN tunnel to the application
C.A ZTNA server and a ZTNA rule
D.A firewall policy with SSL inspection enabled
AnswerC

A ZTNA server defines the internal application's host and port, while a ZTNA rule (configured in the firewall policy) specifies who can access it and what access proxy settings apply. Together they establish the FortiGate as an access proxy that authenticates users and enforces least-privilege access. Without these two objects, the FortiGate has no way to publish or protect the application, making them the core requirement for zero-trust network access.

Why this answer

FortiGate ZTNA requires configuring a ZTNA server (which defines the protected application, its real server, and the access proxy/certificate) and a ZTNA rule (which binds the server to users/groups and enforcement). Together they let the FortiGate act as an access proxy that authenticates users and brokers connections to the internal app without a full VPN tunnel.

Exam trap

NSE4 often tests whether candidates confuse ZTNA with traditional SSL VPN — the trap is selecting 'VPN tunnel' because ZTNA sounds like remote access, when ZTNA's defining feature is the access proxy (ZTNA server + rule) that avoids a full tunnel.

How to eliminate wrong answers

Option A is wrong because FortiClient EMS is used for endpoint posture and ZTNA client management, but it is not strictly required to configure the ZTNA server and rule on the FortiGate itself. Option B is wrong because ZTNA is specifically designed to avoid full VPN tunnels — it uses an access proxy, so a VPN tunnel to the application is not the ZTNA mechanism. Option D is wrong because a firewall policy with SSL inspection is a general security control, not the ZTNA configuration; ZTNA needs the dedicated ZTNA server and rule objects.

94
MCQeasy

Which log severity level indicates that the system is unusable?

A.Error
B.Critical
C.Alert
D.Emergency
AnswerD

Emergency is the highest severity level (0) in FortiGate's logging hierarchy and specifically denotes that the system is unusable, as seen with a kernel panic, critical hardware failure, or complete resource exhaustion. When a FortiGate logs at Emergency severity, the device has either crashed or lost its ability to function, requiring manual intervention or a reboot. This exact definition matches the question's criterion, confirming Emergency as the correct answer.

Why this answer

The Emergency severity level (level 0) indicates that the system is unusable. It is the highest severity level in syslog (RFC 5424) and is used for catastrophic failures. Alert (level 1) indicates immediate action needed, Critical (level 2) indicates critical conditions, and Error (level 3) indicates error conditions, but Emergency specifically means the system is unusable.

Exam trap

The trap is confusing Emergency with Alert or Critical; candidates might think Alert means the system is unusable, but Emergency is the only level that explicitly indicates that.

How to eliminate wrong answers

Option A is wrong because Error (level 3) indicates non-critical errors that don't render the system unusable. Option B is wrong because Critical (level 2) indicates critical conditions but the system may still be partially operational. Option C is wrong because Alert (level 1) requires immediate action but does not necessarily mean the system is unusable.

95
MCQhard

In an active-active HA cluster, session synchronization is configured. A new session is created on the primary unit. When does the secondary unit learn about this session?

A.During the next heartbeat interval
B.After the session is closed
C.Within a few milliseconds to seconds after creation
D.Immediately upon session creation
AnswerC

In FortiGate active-active HA, session synchronization is triggered periodically (default every 200 ms) as well as on immediate state changes such as session setup or teardown. Because of this periodic timer, a newly created session is typically copied to the secondary within a few hundred milliseconds to a couple of seconds, giving the secondary nearly up-to-date state without the performance overhead of instantaneous synchronous replication on every packet.

Why this answer

In an active-active HA cluster, FortiGate performs real-time session synchronization (session-pickup) between cluster members over the HA heartbeat link. When a new session is created on the primary, the session table entry is pushed to the secondary almost instantly — typically within milliseconds, though under load it can take up to a few seconds. This ensures that if a failover occurs, existing sessions continue without being dropped.

Exam trap

NSE4 often tests the misconception that HA synchronization happens on a fixed heartbeat schedule, when in fact session state is replicated continuously and asynchronously as sessions are created or updated.

How to eliminate wrong answers

Option A is wrong because session synchronization is event-driven and continuous, not batched at heartbeat intervals — heartbeats carry HA state, not session tables. Option B is wrong because waiting until session close would defeat the purpose of HA session pickup; failover would drop all active sessions. Option D is wrong because 'immediately' implies zero latency, but synchronization is asynchronous and subject to processing/network delay, so a small but nonzero delay always exists.

96
MCQmedium

A network engineer is configuring an SD-WAN rule to steer voice traffic to the MPLS link with the lowest latency. The SLA target is set to latency < 50 ms and jitter < 10 ms. However, the MPLS link occasionally exceeds the latency threshold. What should the engineer do to ensure voice traffic uses the best available link without manual intervention?

A.Remove the latency performance SLA and rely only on jitter.
B.Configure the SD-WAN rule with a secondary strategy to use the broadband link when SLA is not met.
C.Increase the jitter threshold to 15 ms to avoid SLA violations.
D.Disable SLA enforcement on the SD-WAN rule so voice traffic always uses the MPLS link.
AnswerB

A correct fix is to set the SD-WAN rule to use the broadband link as a secondary strategy when the primary MPLS link fails its performance SLA. In Fortinet, this is done by listing multiple link members in the rule and specifying a strategy such as 'best quality' or 'SLA' where the next available member is used as a backup. The rule then automatically moves voice traffic to broadband whenever the MPLS link violates the configured latency threshold.

Why this answer

Configuring a secondary strategy (e.g., fallback to broadband) allows the SD-WAN rule to automatically steer voice traffic to the best available link when the primary MPLS link fails the SLA (latency > 50 ms). This ensures continuous SLA compliance without manual intervention, leveraging Fortinet's SD-WAN dynamic path selection based on real-time performance metrics.

Exam trap

The trap here is that candidates often think increasing SLA thresholds or disabling SLA enforcement solves the problem, but the correct approach is to implement a fallback strategy to maintain SLA compliance automatically.

How to eliminate wrong answers

Option A is wrong because removing the latency SLA eliminates the ability to detect high-latency conditions, which could lead to poor voice quality on the MPLS link; jitter alone does not guarantee acceptable one-way delay. Option C is wrong because increasing the jitter threshold to 15 ms does not address the latency violation (which is the actual SLA failure), and it may allow unacceptable jitter levels that degrade voice quality. Option D is wrong because disabling SLA enforcement forces all voice traffic to the MPLS link regardless of its performance, defeating the purpose of SD-WAN intelligent steering and risking poor user experience when latency spikes.

97
MCQmedium

A FortiGate admin wants to send logs to both a local disk and a remote FortiAnalyzer. Which log configuration must be set?

A.Use the 'diagnose debug application log' command
B.Select 'Mirror local logs to FortiAnalyzer'
C.Enable local logging and configure FortiAnalyzer as a remote server
D.Set the log severity to 'Information' on both
AnswerC

The correct approach is to enable two independent log destinations in the FortiGate's log settings: first, set the local disk as a log destination (config log disk set status enable), and second, add and enable the FortiAnalyzer as a remote log server (config log fortianalyzer set status enable set server <fortianalyzer_IP>). Each destination is configured in its own block with its own severity/filter settings, and FortiGate will deliver logs to both simultaneously once both are enabled. This matches the requirement to send logs to both a local disk and a FortiAnalyzer without any dependency between the two.

Why this answer

To send logs to both local disk and a remote FortiAnalyzer, you must enable local logging (so logs are written to disk) and configure FortiAnalyzer as a remote logging server. FortiOS supports simultaneous local and remote logging when both are enabled; no special 'mirror' toggle is required for FortiAnalyzer in standard configurations. This combination satisfies the requirement of dual destinations.

Exam trap

NSE4 often tests whether candidates know that local and remote logging are configured independently, so they pick a non-existent 'mirror' option instead of enabling both destinations.

How to eliminate wrong answers

Option A is wrong because 'diagnose debug application log' is a debug command for troubleshooting the logging daemon, not a configuration method for sending logs to two destinations. Option B is wrong because 'Mirror local logs to FortiAnalyzer' is not a standard FortiOS log configuration setting; logging to FortiAnalyzer is configured by adding it as a remote log server. Option D is wrong because log severity controls which events are logged, not where logs are sent; it does not enable dual-destination logging.

98
Multi-Selectmedium

Which TWO statements about FortiGate HA heartbeat interfaces are correct?

Select 2 answers
A.Heartbeat interfaces must be in the same VDOM.
B.Heartbeat interfaces must be dedicated management ports.
C.Heartbeat interfaces must be on the same subnet.
D.Heartbeat traffic is not encrypted by default.
E.Only two heartbeat interfaces can be configured.
AnswersC, D

For HA heartbeat to work, the heartbeat interfaces on both FortiGates must be in the same subnet, typically via a direct crossover connection or through a switch on the same VLAN. This is because heartbeat packets are sent as Ethernet frames (often multicast) and require Layer 2 adjacency; without a shared broadcast domain, the units cannot detect each other or exchange session-synchronization data. If the heartbeat interfaces are on different subnets, the HA cluster will never form.

Why this answer

FortiGate HA heartbeat interfaces must be on the same subnet to allow the heartbeat packets (typically UDP port 496) to be exchanged directly between the primary and secondary units. This ensures Layer 2 adjacency is maintained for reliable failure detection and synchronization.

Exam trap

The trap here is that candidates often assume heartbeat interfaces must be in the same VDOM (Option A) because they think VDOM boundaries restrict HA communication, but FortiGate HA operates at the system level and can use interfaces from different VDOMs as long as they share a subnet.

99
MCQeasy

Which CLI command is used on a FortiGate to perform a real-time packet capture on an interface?

A.diagnose sniffer packet
B.execute packet-capture
C.diagnose debug flow
D.diagnose sys session list
AnswerA

The `diagnose sniffer packet` command is the definitive FortiOS CLI for real-time packet capture. It allows you to specify an interface (e.g., `any`, `port1`), a BPF-style filter (e.g., `host 10.0.0.1`), and a verbose level (0-4) to inspect raw packet headers and payloads as they traverse the FortiGate. This is the standard tool for live traffic analysis and packet-level troubleshooting.

Why this answer

On a FortiGate, the real-time packet capture command is 'diagnose sniffer packet <interface> <filter> <verbose> <count> <timestamp>'. It captures live packets on a specified interface with optional BPF-style filters and verbosity levels, making it the standard tool for troubleshooting traffic at the packet level. This is the FortiOS equivalent of tcpdump.

Exam trap

NSE4 often tests the distinction between packet capture ('diagnose sniffer packet') and flow tracing ('diagnose debug flow') — candidates pick debug flow because it sounds more diagnostic, but only the sniffer captures raw packets.

How to eliminate wrong answers

Option B is wrong because 'execute packet-capture' is not a valid FortiOS CLI command — 'execute' commands handle system actions like reboot, backup, or ping, not packet sniffing. Option C is wrong because 'diagnose debug flow' traces the lifecycle of a packet through the FortiGate's policy and routing engine (showing allow/deny decisions), but it does not capture raw packet contents like a sniffer. Option D is wrong because 'diagnose sys session list' displays the session table (active flows, NAT translations, timeouts), not packet payloads — it is a state inspection tool, not a capture tool.

100
MCQhard

An administrator runs 'diagnose debug flow' for a specific source IP and sees the output includes 'no matching policy'. The FortiGate has a firewall policy that should match the traffic. What is the most likely reason for this message?

A.The FortiGate's routing table does not have a route for the destination
B.The firewall policy is disabled or the source/destination interfaces do not match the traffic's ingress/egress interfaces
C.The security profiles applied to the policy are blocking the traffic
D.The session table is full and cannot accept new sessions
AnswerB

The debug flow output showing 'no matching policy' means the packet successfully completed route lookup and is now being matched against firewall policies. This error occurs when no enabled policy satisfies the traffic's characteristics, such as the ingress interface, egress interface, source/destination addresses, or destination port. A disabled policy is ignored entirely, and if the source or destination interfaces in a policy do not match the actual interfaces the traffic traverses, that policy will be skipped, leaving the traffic without a match.

Why this answer

'No matching policy' in diagnose debug flow means the FortiGate evaluated the packet against the policy list and found no policy whose ingress interface, egress interface, source, destination, schedule, and service all matched. The most common causes are a disabled policy or an interface mismatch (traffic arriving on an interface the policy does not list as incoming).

Exam trap

NSE4 often tests the distinction between routing failures, policy lookup failures, and session-table exhaustion — candidates see 'no matching policy' and wrongly blame routing or security profiles.

How to eliminate wrong answers

Option A is wrong because a missing route produces a different debug message (e.g., 'no route found' or 'reverse path check fail'), not 'no matching policy'. Option C is wrong because security profiles are evaluated only after a policy matches; if no policy matches, profiles are never reached. Option D is wrong because a full session table yields messages like 'session setup failed' or 'no free session', not a policy lookup failure.

101
Multi-Selecthard

Which THREE statements about SD-WAN rules are correct?

Select 3 answers
A.SD-WAN rules are evaluated in order of priority.
B.SD-WAN rules must use a 'load balancing' strategy.
C.SD-WAN rules can match based on application, destination, or source.
D.Each SD-WAN rule can only contain one member.
E.If no SD-WAN rule matches, the traffic is processed by the implicit rule.
AnswersA, C, E

SD-WAN rules are evaluated in order of priority, meaning the rule with the lowest priority number (highest precedence) is inspected first and the first matching rule is applied exclusively. FortiGate processes rules top-down, and once a match is found, no subsequent SD-WAN rule is considered for that session, making priority sequencing critical for deterministic traffic steering.

Why this answer

SD-WAN rules are evaluated in order of priority, meaning the rule with the highest priority (lowest number) is matched first. This sequential evaluation ensures deterministic traffic steering based on the most specific match criteria defined by the administrator.

Exam trap

The trap here is that candidates often assume SD-WAN rules must use load balancing, but Fortinet allows multiple strategies including 'best quality' and 'manual', and they also mistakenly think each rule can only have one member, whereas member groups are supported for redundancy and load distribution.

← PreviousPage 2 of 2 · 101 questions total

Ready to test yourself?

Try a timed practice session using only Nse4 Ha Diagnostics questions.