NSE7 Troubleshooting and Diagnostics Practice Question
A FortiGate administrator is troubleshooting a policy that is supposed to allow HTTP traffic from an internal subnet to a web server. Users report that they cannot access the web server. The administrator runs 'diagnose debug flow' and sees that the traffic is being denied by policy 0. What is the most likely cause?
⚠ Common exam trap
The trap here is assuming that policy 0 is a valid policy or that a security profile is blocking, but policy 0 indicates that no policy matched the traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy does not match the traffic because of incorrect source or destination interface, address, or service.
When 'diagnose debug flow' shows that traffic is denied by policy 0, it means no firewall policy matched the traffic. The most likely cause is that the policy does not match the traffic due to incorrect configuration of interfaces, addresses, or services. The administrator should verify that the policy's source and destination interfaces and addresses align with the actual traffic, and that the service is correctly set to HTTP. This is a common troubleshooting step for policy mismatches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The traffic is being denied by a security profile.
Why it's wrong here
Security profiles are applied after a policy matches. If a security profile were denying traffic, debug flow would show that the policy matched and then the profile action. Since debug flow shows policy 0, no policy matched at all, so security profiles are not involved. Therefore, this is not the cause.
- ✗
The traffic is being denied by the implicit deny policy.
Why it's wrong here
Policy 0 in debug flow output indicates that no matching policy was found, and the traffic hit the implicit deny. However, the implicit deny is not policy 0; policy 0 is a special policy ID that means no policy matched. The implicit deny is typically policy 0 in debug flow, but the administrator needs to check why no policy matched. The most likely cause is a misconfiguration in the policy, such as wrong source or destination interface, or wrong service.
- ✓
The policy does not match the traffic because of incorrect source or destination interface, address, or service.
Why this is correct
When debug flow shows policy 0, it means no policy matched the traffic. This is often due to mismatched source interface, destination interface, source address, destination address, or service. In this scenario, the administrator should verify that the policy's source and destination interfaces and addresses match the actual traffic, and that the service is set to HTTP. This is the most likely cause and the correct answer.
- ✗
The policy is disabled or does not exist.
Why it's wrong here
If the policy were disabled or did not exist, debug flow would show policy 0 as well. However, the question states that the policy is supposed to allow HTTP traffic, implying it exists. The more specific cause is that the policy does not match the traffic due to incorrect parameters. Disabling the policy is one possibility, but it is not the most likely cause; misconfiguration is more common.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.