NSE7 Troubleshooting and Diagnostics Practice Question
A FortiGate is configured with an explicit web proxy on port 8080. Users report that some websites load slowly while others fail to load at all. The administrator runs 'diagnose debug application wad 8' and sees messages about 'proxy worker' and 'connection failed'. Which command should the administrator use to view the current proxy sessions in real time?
⚠ Common exam trap
The trap here is assuming that the general session list includes proxy session details, but explicit proxy sessions are managed separately by the wad daemon.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose wad session list
The explicit web proxy on FortiGate is handled by the wad daemon. To view current proxy sessions in real time, the administrator should use 'diagnose wad session list'. This command provides details such as client IP, destination, and session state, which are essential for troubleshooting why some websites load slowly or fail. The debug output already indicated wad as the relevant process, making this the correct diagnostic step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
diagnose firewall iprope list
Why it's wrong here
This command shows the IP rope configuration, which defines how traffic is matched to firewall policies, but it does not display active proxy sessions. The issue is about ongoing proxy connections, not policy matching. The administrator needs to see the current sessions handled by the explicit proxy, which are managed by the wad daemon, so this command is not appropriate.
- ✓
diagnose wad session list
Why this is correct
This command displays the current explicit proxy sessions managed by the wad daemon, including source, destination, and state. In this scenario, the administrator needs to see which proxy sessions are active or failing to understand why some websites fail to load. The debug output already points to wad, so listing wad sessions is the correct next step.
- ✗
diagnose debug application proxy -1
Why it's wrong here
There is no 'proxy' debug application on FortiGate; the correct application for explicit proxy is 'wad'. The administrator already used 'diagnose debug application wad 8' to see debug messages. Running a non-existent debug application would produce no useful output and would not help list current proxy sessions. The correct command to list proxy sessions is 'diagnose wad session list'.
- ✗
diagnose sys session list
Why it's wrong here
While this command shows all firewall sessions, it does not specifically filter or detail the explicit proxy sessions handled by the wad daemon. The issue is with the proxy service, so the administrator needs proxy-specific session information. Using the general session list would include many unrelated sessions and not provide the proxy-specific details required to troubleshoot the failing website loads.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.