NSE4 High Availability and Diagnostics Practice Question
Which TWO of the following are valid methods to view real-time debug output on a FortiGate? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose sniffer packet
Diagnose debug flow and diagnose sniffer packet are real-time debug commands. Execute tail log is not a standard command.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
diagnose sniffer packet
Why this is correct
diagnose sniffer packet is the Fortinet CLI command that invokes the built-in packet capture engine to display live packets as they traverse the specified interface(s) or VLAN(s). It accepts real-time filters such as 'port 443' or host IPs, and a verbosity level (1-6) controlling header vs. full payload display. Because it immediately streams captured frames to the terminal, it is a legitimate real-time traffic-viewing tool.
- ✗
diagnose debug enable
Why it's wrong here
diagnose debug enable toggles the global debug flag but does not by itself generate or display any output. To see real-time information, you must first start a specific debug instance (e.g., 'diagnose debug application ftp' or 'diagnose debug flow') that produces data, and then run 'diagnose debug enable' to activate it. Without an active debug source, this command simply sits idle, so it cannot be used alone to view live traffic or events.
- ✗
diagnose sys session list
Why it's wrong here
diagnose sys session list dumps the current session table — a static snapshot of all active sessions, including source/destination IPs, ports, and session states at that exact moment. It does not stream packets or continuously update, so any 'real-time' use would require repeatedly executing it manually or via a script. The output represents established connection state rather than live packet captures, making it a point-in-time inventory rather than a real-time viewing method.
- ✗
execute tail log
Why it's wrong here
execute tail log is not a valid FortiOS CLI command; entering it returns an 'unknown action' or syntax error. While there is an 'execute tail' command for certain limited hardware/file operations (e.g., 'execute tail usb'), it does not tail system logs in real time. To view logs as they are written, administrators use 'log display' or 'execute log display', or enable real-time debug via 'diagnose debug application' — but 'execute tail log' itself is invalid and performs no action.
- ✓
diagnose debug flow
Why this is correct
diagnose debug flow is a real-time troubleshooting tool that traces packet flows through the FortiOS packet-processing pipeline. After setting a filter with 'diagnose debug flow filter', you combine it with 'diagnose debug enable' to see each session's action (accept, drop, or forward) and the reason codes for dropped packets. It streams live event traces to the console as traffic matches the filter, making it a valid real-time method specifically for flow-level inspection rather than raw packet capture.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.