Courseiva

NSE7 Troubleshooting and Diagnostics Practice Question

A FortiGate administrator is troubleshooting a policy that is supposed to allow HTTP traffic from an internal subnet to a web server. Users report that they cannot access the web server. The administrator runs 'diagnose debug flow' and sees that the traffic is being denied by policy 0. What is the most likely cause?

⚠ Common exam trap

The trap here is assuming that policy 0 is a valid policy or that a security profile is blocking, but policy 0 indicates that no policy matched the traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy does not match the traffic because of incorrect source or destination interface, address, or service.

When 'diagnose debug flow' shows that traffic is denied by policy 0, it means no firewall policy matched the traffic. The most likely cause is that the policy does not match the traffic due to incorrect configuration of interfaces, addresses, or services. The administrator should verify that the policy's source and destination interfaces and addresses align with the actual traffic, and that the service is correctly set to HTTP. This is a common troubleshooting step for policy mismatches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The traffic is being denied by a security profile.

    Why it's wrong here

    Security profiles are applied after a policy matches. If a security profile were denying traffic, debug flow would show that the policy matched and then the profile action. Since debug flow shows policy 0, no policy matched at all, so security profiles are not involved. Therefore, this is not the cause.

  • ✗

    The traffic is being denied by the implicit deny policy.

    Why it's wrong here

    Policy 0 in debug flow output indicates that no matching policy was found, and the traffic hit the implicit deny. However, the implicit deny is not policy 0; policy 0 is a special policy ID that means no policy matched. The implicit deny is typically policy 0 in debug flow, but the administrator needs to check why no policy matched. The most likely cause is a misconfiguration in the policy, such as wrong source or destination interface, or wrong service.

  • ✓

    The policy does not match the traffic because of incorrect source or destination interface, address, or service.

    Why this is correct

    When debug flow shows policy 0, it means no policy matched the traffic. This is often due to mismatched source interface, destination interface, source address, destination address, or service. In this scenario, the administrator should verify that the policy's source and destination interfaces and addresses match the actual traffic, and that the service is set to HTTP. This is the most likely cause and the correct answer.

  • ✗

    The policy is disabled or does not exist.

    Why it's wrong here

    If the policy were disabled or did not exist, debug flow would show policy 0 as well. However, the question states that the policy is supposed to allow HTTP traffic, implying it exists. The more specific cause is that the policy does not match the traffic due to incorrect parameters. Disabling the policy is one possibility, but it is not the most likely cause; misconfiguration is more common.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.