NSE7 Troubleshooting and Diagnostics Practice Question
A customer reports intermittent connectivity issues between two internal subnets separated by a FortiGate firewall. The traffic is allowed by the policy, but users experience timeouts during peak hours. Which troubleshooting step should you take first?
⚠ Common exam trap
The trap here is that candidates often jump to packet capture or hardware acceleration as the first step, overlooking the session table as the most common cause of intermittent peak-hour connectivity issues.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the session table for session limits and session congestion.
Intermittent connectivity during peak hours strongly suggests session table exhaustion or session congestion. The FortiGate's session table has a finite capacity, and when it fills up, new sessions are dropped, causing timeouts. Checking the session table for limits and congestion is the fastest, least intrusive first step to confirm whether the firewall is running out of session resources before performing more complex diagnostics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a packet sniffer on the FortiGate to capture traffic between the subnets.
Why it's wrong here
Running a packet sniffer on the FortiGate captures raw traffic but does not diagnose the root cause of intermittent timeouts during peak hours, which is likely buffer exhaustion or session table overflow rather than a policy or packet-level fault. This step is tempting because sniffing is the default tool for verifying whether packets traverse the firewall correctly, and it would be correct if the issue were suspected to be a silent policy drop or asymmetric routing.
- ✓
Check the session table for session limits and session congestion.
Why this is correct
Checking the session table reveals whether sessions are exhausting the FortiGate's session limits or hitting per-policy session thresholds during peak load, which directly explains intermittent timeouts despite a permit policy. This satisfies the stem's peak-hour congestion constraint, since session exhaustion manifests as dropped new connections rather than policy denials.
- ✗
Disable hardware acceleration on the FortiGate.
Why it's wrong here
Disabling hardware acceleration changes how the FortiGate processes packets but does not identify why timeouts occur only at peak hours; it is used to work around offload-related inspection anomalies or specific protocol issues. The first step should gather diagnostic evidence, such as session lists and resource utilisation, before altering forwarding behaviour.
- ✗
Configure SNAT on the policy to translate the source IP.
Why it's wrong here
SNAT rewrites source addresses and does nothing to diagnose peak-hour timeouts; it is configured to provide outbound internet access or hide internal addressing, not to troubleshoot policy-permitted inter-subnet traffic. The first step should instead inspect session and resource utilisation data, such as checking session tables or conserve mode during the peaks.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.