Courseiva

NSE4 High Availability and Diagnostics Practice Question

Which FortiGate diagnostic command allows you to capture packets on an interface for troubleshooting network connectivity issues?

⚠ Common exam trap

NSE4 often tests the distinction between 'diagnose sniffer packet' (packet capture) and 'diagnose debug flow' (flow tracing) — candidates confuse the two when asked about capturing packets on an interface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose sniffer packet

The 'diagnose sniffer packet' command on a FortiGate captures packets on a specified interface, similar to tcpdump. It allows administrators to see live packet data for troubleshooting connectivity, filtering by interface, protocol, host, port, and verbosity level. This is the correct tool for packet-level capture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    diagnose debug flow

    Why it's wrong here

    The `diagnose debug flow` command traces packets through the FortiGate security pipeline, showing session setup, NAT translations, and policy match decisions. However, it is a sampling/debug facility—it prints only a textual trace of packet metadata and processing events to the CLI, not raw packet captures. It helps troubleshoot why traffic is dropped or misrouted, but it cannot provide the actual payload or full packet-by-packet history that a true capture tool offers.

  • ✓

    diagnose sniffer packet

    Why this is correct

    The `diagnose sniffer packet` command is FortiGate's built-in packet capture utility, equivalent to tcpdump. It allows you to capture raw packets on one or more interfaces with flexible BPF-style filters (e.g., host, port, protocol) and verbosity levels (1 for headers, 2 for headers+payload, 3 for full packet details). This is the canonical command for performing a packet capture on FortiGate, making it the correct answer for capturing packets.

  • ✗

    diagnose sys session list

    Why it's wrong here

    The `diagnose sys session list` command dumps the current session table, which records active flows, their source/destination IPs, ports, protocols, and session states. This provides a static snapshot of connection state at a moment in time, but it does not copy any of the packets traversing the firewall. It is useful for verifying whether a session exists or how it is mapped, but it cannot reveal packet contents, payloads, or wire-level traffic patterns, so it is not a packet capture tool.

  • ✗

    diagnose test application

    Why it's wrong here

    The `diagnose test application` command runs internal diagnostic tests for specific FortiGate daemons and processes (e.g., ipsengine, dnsproxy, kernel modules). These tests typically check counters, reset memory, or force specific internal behaviors—none of which involve reading or capturing network packets. It is a low-level debugging and health-check utility, not a traffic capture mechanism, so it cannot be used to capture packets.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.