NSE7 Troubleshooting and Diagnostics Practice Question
An administrator is troubleshooting a FortiGate that is experiencing high CPU usage. The administrator runs 'diagnose sys top' and sees that the 'ipsengine' process is consuming a large amount of CPU. Which two actions should the administrator take to further diagnose and potentially resolve the issue? (Choose two.)
⚠ Common exam trap
The trap here is thinking that restarting the IPS engine or disabling IPS will solve the problem, when the real issue is often misconfiguration or signature overload that requires investigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run 'diagnose debug application ipsmonitor -1' to check for IPS engine restarts or errors.
To diagnose high CPU from the IPS engine, checking the ipsmonitor debug can reveal if the engine is crashing or restarting, which would cause repeated high CPU spikes. Additionally, reviewing the IPS sensor configuration for heavy signatures or excessive signatures can identify if the load is due to inspection complexity. Both actions target the root cause without compromising security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run 'diagnose debug application ipsmonitor -1' to check for IPS engine restarts or errors.
Why this is correct
This command enables debugging for the IPS monitor daemon, which manages the IPS engine processes. It can reveal if the IPS engine is repeatedly restarting due to crashes or configuration issues, which would cause high CPU. The output may show messages about engine failures or memory problems, helping to identify the root cause.
- ✗
Disable IPS inspection on all firewall policies to immediately reduce CPU usage.
Why it's wrong here
Disabling IPS inspection would reduce CPU but at the cost of security. It is not a diagnostic action but a workaround that leaves the network vulnerable. The goal is to diagnose and resolve the issue while maintaining security, not to disable protection. This should only be a last resort after identifying the cause.
- ✗
Increase the FortiGate's memory allocation to the IPS engine via CLI.
Why it's wrong here
FortiGate does not provide a CLI command to increase memory allocation for a specific process like the IPS engine. Memory management is handled by the system, and such an action is not possible. The issue is likely due to configuration or signature complexity, not memory allocation.
- ✓
Check the IPS sensor configuration for overly broad or resource-intensive signatures.
Why this is correct
An IPS sensor with many signatures or those that require heavy pattern matching can cause high CPU usage by the IPS engine. Reviewing the sensor to ensure only necessary signatures are enabled, and possibly using flow-based inspection instead of proxy-based, can reduce CPU load. This is a common cause of high ipsengine CPU.
- ✗
Restart the IPS engine using 'diagnose test application ipsmonitor 99' to clear the high CPU.
Why it's wrong here
While restarting the IPS engine might temporarily alleviate high CPU, it does not address the root cause and could disrupt traffic inspection. The command 'diagnose test application ipsmonitor 99' is not a standard or recommended way to restart the IPS engine; typically, it restarts automatically if it crashes. This action is not a diagnostic step and may cause service interruption.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.