Courseiva
Troubleshooting and DiagnosticsmediumMultiple ChoiceObjective-mapped

NSE7 Troubleshooting and Diagnostics Practice Question

A customer reports intermittent connectivity issues between two internal subnets separated by a FortiGate firewall. The traffic is allowed by the policy, but users experience timeouts during peak hours. Which troubleshooting step should you take first?

⚠ Common exam trap

The trap here is that candidates often jump to packet capture or hardware acceleration as the first step, overlooking the session table as the most common cause of intermittent peak-hour connectivity issues.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Check the session table for session limits and session congestion.

Intermittent connectivity during peak hours strongly suggests session table exhaustion or session congestion. The FortiGate's session table has a finite capacity, and when it fills up, new sessions are dropped, causing timeouts. Checking the session table for limits and congestion is the fastest, least intrusive first step to confirm whether the firewall is running out of session resources before performing more complex diagnostics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Run a packet sniffer on the FortiGate to capture traffic between the subnets.

    Why it's wrong here

    Running a packet sniffer on the FortiGate captures raw traffic but does not diagnose the root cause of intermittent timeouts during peak hours, which is likely buffer exhaustion or session table overflow rather than a policy or packet-level fault. This step is tempting because sniffing is the default tool for verifying whether packets traverse the firewall correctly, and it would be correct if the issue were suspected to be a silent policy drop or asymmetric routing.

  • Check the session table for session limits and session congestion.

    Why this is correct

    Peak hour timeouts often indicate session table exhaustion; checking this is the quickest diagnostic step.

  • Disable hardware acceleration on the FortiGate.

    Why it's wrong here

    This could reduce performance and is not a first step in troubleshooting intermittent connectivity.

  • Configure SNAT on the policy to translate the source IP.

    Why it's wrong here

    SNAT is not a troubleshooting step and may not resolve the issue.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 940 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.