Courseiva

NSE7 Troubleshooting and Diagnostics Practice Question

An administrator needs to verify that a FortiGate is correctly matching a firewall policy for traffic from 192.168.1.0/24 to 10.0.0.0/8. Which command provides a list of policies that match a given source and destination?

⚠ Common exam trap

Watch out — candidates often confuse configuration display commands like 'show firewall policy' with dynamic lookup tools that actually simulate the policy matching process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose firewall policy lookup

The 'diagnose firewall policy lookup' command is designed to simulate a policy lookup based on specified parameters such as source IP, destination IP, and incoming interface. It returns the policy ID that would be matched, making it the ideal tool for verifying policy matching for specific traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    diagnose debug flow filter

    Why it's wrong here

    This command sets filters for debug flow output, but it does not list policies. It is used in conjunction with debug flow to trace packets, but it does not directly answer which policy matches a given source and destination without additional steps and interpretation.

  • ✗

    diagnose firewall iprope list 100004

    Why it's wrong here

    This command lists the IP rope entries, which are used for early packet processing and do not directly show firewall policy matches. While it can be useful for troubleshooting policy routing, it does not provide a direct list of policies that match specific source and destination criteria as needed here.

  • ✓

    diagnose firewall policy lookup

    Why this is correct

    The 'diagnose firewall policy lookup' command allows the administrator to specify source and destination IP addresses, interfaces, and other parameters, and it returns the policy that matches the traffic. This is exactly what is needed to verify which policy is being applied to the given traffic.

  • ✗

    show firewall policy

    Why it's wrong here

    This command displays the entire firewall policy configuration, but it does not simulate a lookup for specific traffic. The administrator would have to manually parse the list to determine which policy matches, which is error-prone. It does not provide the dynamic matching capability needed.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.