NSE4 System and Network Administration Practice Question
You run 'get system performance status' and see CPU usage at 95% with high context switch rate. The FortiGate is not passing any traffic. What is the most likely cause?
⚠ Common exam trap
The trap here is that candidates often associate high CPU usage with a DDoS attack, but the key clue is the high context switch rate combined with zero traffic passing, which points to a routing loop rather than a flood of traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A routing loop is causing continuous packet processing
A routing loop causes the FortiGate to continuously process and re-process packets as they are forwarded in a cycle between routers, leading to high CPU usage and context switch rates. The loop prevents traffic from being successfully delivered, resulting in zero traffic passing through the FortiGate. This matches the observed symptoms of 95% CPU usage and high context switching.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A routing loop is causing continuous packet processing
Why this is correct
A routing loop occurs when packets are repeatedly forwarded between interfaces or virtual domains without reaching a final destination, causing the kernel's forwarding engine to process the same packet iteratively. This can happen with static routes pointing to each other or with dynamic routing protocol inconsistencies, and on FortiGate it often shows high CPU in the kernel's netlink or IP forwarding process. Since the loop re-injects packets into the forwarding pipeline even in the absence of external traffic (e.g., from self-originated packets or multicast), it can sustain 95% CPU utilization.
- ✗
The FortiGate is under a DDoS attack
Why it's wrong here
A DDoS attack is characterized by a flood of malicious packets consuming bandwidth, session table resources, or proxy CPU. On FortiGate, you would see high PPS/throughput counters, many new sessions in the session table, and likely interface bandwidth utilization near line rate. With no traffic passing and no increase in session establishment rates, a DDoS attack cannot explain isolated high CPU; moreover, attack traffic would typically appear in top talkers or the via-packet diagnostics.
- ✗
The antivirus engine is updating signatures
Why it's wrong here
Signature updates are periodic, small downloads that trigger a one-time decompression and database rebuild, causing CPU usage to spike for a few seconds to a minute. On FortiGate, the update process is CPU-bound but it completes quickly and does not continuously re-run unless a forced update loop occurs (which is not normal). A sustained 95% CPU usage over an observed 'get system performance status' snapshot would not align with the transient nature of signature updates; also, update processes appear as separate processes in top and can be verified.
- ✗
The FortiGate is in transparent mode
Why it's wrong here
Transparent mode (Layer 2) merely changes how the FortiGate interfaces are bridged, eliminating routing decisions for traffic that stays within the same L2 domain. CPU processing is primarily driven by features like firewall policies, IPS, antivirus, and traffic volume, not by the operation mode itself. In transparent mode, all interfaces share a single IP and traffic is forwarded based on MAC addresses at Layer 2, but this is not a CPU-intensive operation; in fact, it can be less CPU-intensive than routed mode because routing lookups are simplified. Therefore, high CPU would point to a policy, anomaly, or configuration issue rather than the mode itself.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.