NSE4 High Availability and Diagnostics Practice Question
Which FortiGate feature allows administrators to verify if a specific IP address is being blocked by a security policy?
⚠ Common exam trap
NSE4 often tests the confusion between session listing and flow tracing, leading candidates to choose 'diagnose sys session list' when they need to see policy enforcement details.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose debug flow
The 'diagnose debug flow' command allows administrators to trace the path of a packet through the FortiGate, showing which security policy, routing, and other checks it matches. By filtering on a specific IP address, administrators can see if traffic from that IP is being blocked by a policy and the reason for the block.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
diagnose sys session list
Why it's wrong here
This command lists entries in the session table maintained by the kernel for tracked connections. It shows active flows, their source/destination interfaces, IPs, ports, and the associated policy ID, but it does not reveal whether a packet was dropped or blocked by firewall policy. Since denied traffic does not create a session, this command cannot be used to verify why a specific flow was denied, only to confirm which sessions are currently established.
- ✗
get system ha status
Why it's wrong here
This command displays FortiGate high availability (HA) operational state, such as cluster role (primary/secondary), synchronization status, and monitored links. It has nothing to do with firewall policy processing or traffic decision-making; it is used to diagnose HA issues like failover or session sync problems. Therefore, it cannot show whether a particular session was permitted or blocked by policy.
- ✓
diagnose debug flow
Why this is correct
This command runs a trace of a specific user-selected packet or flow through the FortiGate's processing pipeline, displaying each stage including policy lookup, routing decisions, and the final action (accept or drop). It captures the exact policy ID matched and the reason for any drop, such as implicit deny or traffic-shaping constraints. As a debug utility, it is the proper tool for verifying the policy decision for a given flow, making it the correct answer.
- ✗
diagnose sniffer packet
Why it's wrong here
This is a packet capture tool that reflects real-time traffic visibility by showing raw packets traversing the FortiGate interfaces, including headers and payload, but it does not report the firewall policy lookup results. It lacks the stateful context of how the FortiGate classified the traffic, so it cannot tell you whether a packet was accept or denied by policy. Hence, it is not used to validate policy decisions.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator is troubleshooting a policy that should allow HTTP traffic but it is being blocked. They run 'diagnose debug flow' and see the output ends with 'msg=deny by forward policy check'. What is the most likely cause?
medium- ✓ A.The policy is configured with action DENY
- B.The routing table is missing a default route
- C.The session table is full
- D.The HTTP traffic is not matching any policy
Why A: The message indicates the packet was denied by a firewall policy, meaning there is no matching policy or the matching policy has action DENY.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.