NSE4 High Availability and Diagnostics Practice Question
Which CLI command is used on a FortiGate to perform a real-time packet capture on an interface?
⚠ Common exam trap
NSE4 often tests the distinction between packet capture ('diagnose sniffer packet') and flow tracing ('diagnose debug flow') — candidates pick debug flow because it sounds more diagnostic, but only the sniffer captures raw packets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose sniffer packet
On a FortiGate, the real-time packet capture command is 'diagnose sniffer packet <interface> <filter> <verbose> <count> <timestamp>'. It captures live packets on a specified interface with optional BPF-style filters and verbosity levels, making it the standard tool for troubleshooting traffic at the packet level. This is the FortiOS equivalent of tcpdump.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
diagnose sniffer packet
Why this is correct
The `diagnose sniffer packet` command is the definitive FortiOS CLI for real-time packet capture. It allows you to specify an interface (e.g., `any`, `port1`), a BPF-style filter (e.g., `host 10.0.0.1`), and a verbose level (0-4) to inspect raw packet headers and payloads as they traverse the FortiGate. This is the standard tool for live traffic analysis and packet-level troubleshooting.
- ✗
execute packet-capture
Why it's wrong here
The command `execute packet-capture` is not a valid FortiOS command. FortiOS reserves the `execute` branch for administrative operations such as `execute reboot`, `execute shutdown`, or `execute ping`, not for diagnostic captures. To perform a packet capture, you must use the `diagnose` branch, specifically `diagnose sniffer packet`. Typing `execute packet-capture` will result in a syntax or unknown command error.
- ✗
diagnose debug flow
Why it's wrong here
The `diagnose debug flow` command is designed for flow tracing, not packet capture. It enables and displays debug logs for the firewall's session-processing pipeline, including policy lookup, NAT decisions, and routing, but it does not show raw packet headers or payloads. This command is useful for understanding why a session is dropped or misrouted, but it cannot capture the actual packets on the wire like a sniffer can.
- ✗
diagnose sys session list
Why it's wrong here
The `diagnose sys session list` command displays the current session table, which contains information about active sessions such as source/destination IPs, ports, protocol, and session state. It is a snapshot of the connection table, not a real-time packet capture. While it helps verify whether a session exists or its state, it does not provide per-packet visibility and cannot capture data flowing across an interface.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.