NSE4 High Availability and Diagnostics Practice Question
Which FortiGate diagnostic command allows you to capture packets on an interface for troubleshooting network connectivity issues?
⚠ Common exam trap
NSE4 often tests the distinction between 'diagnose sniffer packet' (packet capture) and 'diagnose debug flow' (flow tracing) — candidates confuse the two when asked about capturing packets on an interface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose sniffer packet
The 'diagnose sniffer packet' command on a FortiGate captures packets on a specified interface, similar to tcpdump. It allows administrators to see live packet data for troubleshooting connectivity, filtering by interface, protocol, host, port, and verbosity level. This is the correct tool for packet-level capture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
diagnose debug flow
Why it's wrong here
The `diagnose debug flow` command traces packets through the FortiGate security pipeline, showing session setup, NAT translations, and policy match decisions. However, it is a sampling/debug facility—it prints only a textual trace of packet metadata and processing events to the CLI, not raw packet captures. It helps troubleshoot why traffic is dropped or misrouted, but it cannot provide the actual payload or full packet-by-packet history that a true capture tool offers.
- ✓
diagnose sniffer packet
Why this is correct
The `diagnose sniffer packet` command is FortiGate's built-in packet capture utility, equivalent to tcpdump. It allows you to capture raw packets on one or more interfaces with flexible BPF-style filters (e.g., host, port, protocol) and verbosity levels (1 for headers, 2 for headers+payload, 3 for full packet details). This is the canonical command for performing a packet capture on FortiGate, making it the correct answer for capturing packets.
- ✗
diagnose sys session list
Why it's wrong here
The `diagnose sys session list` command dumps the current session table, which records active flows, their source/destination IPs, ports, protocols, and session states. This provides a static snapshot of connection state at a moment in time, but it does not copy any of the packets traversing the firewall. It is useful for verifying whether a session exists or how it is mapped, but it cannot reveal packet contents, payloads, or wire-level traffic patterns, so it is not a packet capture tool.
- ✗
diagnose test application
Why it's wrong here
The `diagnose test application` command runs internal diagnostic tests for specific FortiGate daemons and processes (e.g., ipsengine, dnsproxy, kernel modules). These tests typically check counters, reset memory, or force specific internal behaviors—none of which involve reading or capturing network packets. It is a low-level debugging and health-check utility, not a traffic capture mechanism, so it cannot be used to capture packets.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.