NSE7 Troubleshooting and Diagnostics Practice Question
A FortiGate administrator needs to verify that the firewall is correctly identifying and logging a specific application, 'Facebook', that is being used by internal users. The administrator has already configured an application control profile with logging enabled for Facebook. Which CLI command should the administrator use to view the application control logs in real-time?
⚠ Common exam trap
Many exam-takers confuse IPS engine debugging with application control debugging; they are separate processes, and only the appctrl debug shows application control logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose debug application appctrl -1
To view application control logs in real-time, the administrator should use the debug command for the application control daemon. The 'diagnose debug application appctrl -1' command provides detailed output about application identification and logging decisions. This is more specific than general debug commands and directly addresses the need to verify that Facebook is being identified and logged. Other commands like ipsmonitor debug or session list do not provide the same level of detail for application control logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
diagnose debug enable
Why it's wrong here
'diagnose debug enable' turns on debugging output for the current console session, but it does not specify which application or log to display. Without additional filters or application-specific debug commands, it will not show application control logs. It is a general command that must be combined with other debug commands to be useful.
- ✓
diagnose debug application appctrl -1
Why this is correct
The command 'diagnose debug application appctrl -1' enables debug output for the application control daemon, which shows real-time information about application identification and logging. This allows the administrator to see when Facebook is detected and logged. It is the most direct way to verify application control logging in real-time.
- ✗
diagnose sys session list
Why it's wrong here
'diagnose sys session list' displays the current session table, including some application information if available. However, it does not show application control log entries in real-time. It can be used to check if a session is being identified as a specific application, but it is not the command for viewing logs.
- ✗
diagnose debug application ipsmonitor -1
Why it's wrong here
This command enables debug output for the IPS monitor, which is related to intrusion prevention and application control processing. However, it does not display application control logs in real-time; it shows internal engine messages. It is useful for troubleshooting IPS engine behavior but not for viewing application control log entries.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.