Courseiva

NSE7 Troubleshooting and Diagnostics Practice Question

A FortiGate is configured with a firewall policy that has a URL filter profile. Users report that access to a specific website is blocked, but the administrator wants to verify which URL filter category matched the request. The administrator runs 'diagnose debug application urlfilter -1' in the CLI. However, no output appears. What is the MOST likely reason for the lack of output?

⚠ Common exam trap

The trap here is assuming that setting the debug level automatically enables debug output, when in fact a separate global enable command is required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The administrator did not run 'diagnose debug enable' after setting the debug level.

To capture URL filter debug messages, the administrator must set the debug level for the urlfilter application and then enable debug globally. The command 'diagnose debug application urlfilter -1' sets the level, but without 'diagnose debug enable', no output is generated. This is a common troubleshooting step that is often missed. Once enabled, the debug will show category matches and other details.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The urlfilter debug application is not available on this FortiGate model or firmware version.

    Why it's wrong here

    The urlfilter debug application is a standard diagnostic tool available on most FortiGate models running FortiOS. It is used to troubleshoot URL filtering issues. While some debug applications may be model-specific, urlfilter is commonly present. The lack of output is more likely due to debug not being enabled globally, not due to unavailability. This option is plausible but incorrect for this scenario.

  • ✗

    The URL filter profile is not applied to the firewall policy that matches the user traffic.

    Why it's wrong here

    If the URL filter profile were not applied, the website would not be blocked by URL filtering. The scenario states that access is blocked, implying the profile is active. The issue is not the profile application but the debug output. Even if the profile were applied, the debug would show matches if enabled. Therefore, this is not the most likely reason for no output.

  • ✗

    The URL filter debug level is set to 0 by default and must be enabled with 'diagnose debug enable'.

    Why it's wrong here

    While 'diagnose debug enable' is necessary to activate debug output, the urlfilter application debug level starts at 0. The administrator must first set the level with 'diagnose debug application urlfilter -1' and then enable debug. However, the command itself sets the level, so the missing step is likely that debug was not enabled. This option incorrectly states that the level is set to 0 by default; setting it with -1 overrides that. The real issue is that debug output is not enabled globally.

  • ✓

    The administrator did not run 'diagnose debug enable' after setting the debug level.

    Why this is correct

    In FortiOS, to view debug output for a specific application, you must first set the debug level using 'diagnose debug application <name> <level>' and then enable debug globally with 'diagnose debug enable'. Without enabling debug, no output is displayed even if the level is set. This is a common oversight. The command 'diagnose debug application urlfilter -1' sets the level to verbose, but debug remains disabled until 'diagnose debug enable' is issued.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.