NSE7 Troubleshooting and Diagnostics Practice Question
An administrator is troubleshooting a FortiGate that is experiencing high CPU usage. The administrator runs 'diagnose sys top' and observes that the 'ipsengine' process is consuming a large amount of CPU. The administrator suspects that a specific IPS signature is causing the issue. Which command should the administrator use to identify which IPS signature is triggering the high CPU usage?
⚠ Common exam trap
Many exam-takers confuse general IPS debugging commands with those that provide per-signature CPU statistics.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose test application ipsengine 4
The 'diagnose test application ipsengine 4' command is specifically designed to show the top IPS signatures by CPU usage, allowing the administrator to identify which signature is causing high CPU. Other commands provide general IPS or session information but do not drill down to per-signature CPU consumption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
diagnose sys session full-stat
Why it's wrong here
The 'diagnose sys session full-stat' command provides statistics about session table usage, such as the number of sessions and memory usage, but it does not relate to IPS signatures or CPU usage. It is irrelevant for identifying a CPU-intensive IPS signature.
- ✗
diagnose ips anomaly list
Why it's wrong here
The 'diagnose ips anomaly list' command displays the current anomaly statistics, such as protocol anomalies, but it does not provide per-signature CPU usage or identify which signature is causing high CPU. It is useful for detecting anomalies but not for pinpointing a specific signature.
- ✓
diagnose test application ipsengine 4
Why this is correct
The command 'diagnose test application ipsengine 4' displays the top IPS signatures by CPU usage, helping identify which signature is causing high CPU. This is the correct tool for pinpointing a specific signature that is consuming excessive CPU resources.
- ✗
diagnose debug application ipsmonitor -1
Why it's wrong here
Enabling ipsmonitor debug with 'diagnose debug application ipsmonitor -1' shows messages related to the IPS monitor process, such as engine restarts, but it does not give details about which signature is consuming CPU. It is more for monitoring the health of the IPS engine.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.