Courseiva

NSE4 High Availability and Diagnostics Practice Question

Which FortiGate feature allows administrators to verify if a specific IP address is being blocked by a security policy?

⚠ Common exam trap

NSE4 often tests the confusion between session listing and flow tracing, leading candidates to choose 'diagnose sys session list' when they need to see policy enforcement details.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose debug flow

The 'diagnose debug flow' command allows administrators to trace the path of a packet through the FortiGate, showing which security policy, routing, and other checks it matches. By filtering on a specific IP address, administrators can see if traffic from that IP is being blocked by a policy and the reason for the block.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    diagnose sys session list

    Why it's wrong here

    This command lists entries in the session table maintained by the kernel for tracked connections. It shows active flows, their source/destination interfaces, IPs, ports, and the associated policy ID, but it does not reveal whether a packet was dropped or blocked by firewall policy. Since denied traffic does not create a session, this command cannot be used to verify why a specific flow was denied, only to confirm which sessions are currently established.

  • ✗

    get system ha status

    Why it's wrong here

    This command displays FortiGate high availability (HA) operational state, such as cluster role (primary/secondary), synchronization status, and monitored links. It has nothing to do with firewall policy processing or traffic decision-making; it is used to diagnose HA issues like failover or session sync problems. Therefore, it cannot show whether a particular session was permitted or blocked by policy.

  • ✓

    diagnose debug flow

    Why this is correct

    This command runs a trace of a specific user-selected packet or flow through the FortiGate's processing pipeline, displaying each stage including policy lookup, routing decisions, and the final action (accept or drop). It captures the exact policy ID matched and the reason for any drop, such as implicit deny or traffic-shaping constraints. As a debug utility, it is the proper tool for verifying the policy decision for a given flow, making it the correct answer.

  • ✗

    diagnose sniffer packet

    Why it's wrong here

    This is a packet capture tool that reflects real-time traffic visibility by showing raw packets traversing the FortiGate interfaces, including headers and payload, but it does not report the firewall policy lookup results. It lacks the stateful context of how the FortiGate classified the traffic, so it cannot tell you whether a packet was accept or denied by policy. Hence, it is not used to validate policy decisions.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator is troubleshooting a policy that should allow HTTP traffic but it is being blocked. They run 'diagnose debug flow' and see the output ends with 'msg=deny by forward policy check'. What is the most likely cause?

medium
  • ✓ A.The policy is configured with action DENY
  • B.The routing table is missing a default route
  • C.The session table is full
  • D.The HTTP traffic is not matching any policy

Why A: The message indicates the packet was denied by a firewall policy, meaning there is no matching policy or the matching policy has action DENY.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.