Courseiva

NSE7 Troubleshooting and Diagnostics Practice Question

An administrator notices that a FortiGate's CPU is consistently high, and the performance dashboard shows the 'ipsengine' process consuming most CPU. The administrator suspects a specific traffic pattern is overwhelming the IPS engine. Which CLI command should be used to identify the top sessions by bandwidth that may be triggering the IPS engine?

⚠ Common exam trap

Watch out — candidates often confuse process monitoring commands (like diagnose sys top) with session monitoring commands that sort by bandwidth.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose sys session top

High CPU on the IPS engine often results from a few heavy sessions. The diagnose sys session top command lists the top sessions by bandwidth, allowing the administrator to quickly identify the offending traffic. This is more direct than dumping all sessions or looking at interface statistics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    diagnose sys session list

    Why it's wrong here

    diagnose sys session list dumps all current sessions with details such as source, destination, and protocol, but it does not sort or summarize by bandwidth. While it can be filtered, it is not the most efficient way to find top bandwidth consumers and does not directly link to IPS engine load.

  • ✓

    diagnose sys session top

    Why this is correct

    diagnose sys session top shows the top sessions sorted by bandwidth usage. This command is ideal for identifying which sessions are consuming the most traffic, which can help determine if a particular flow is causing high IPS engine CPU. It provides a concise list of top sessions with source, destination, and bandwidth.

  • ✗

    diagnose netlink top

    Why it's wrong here

    diagnose netlink top is used to display top network interfaces or VLANs by traffic, not top sessions. It provides aggregate throughput per interface, which might hint at heavy traffic, but it cannot pinpoint which specific sessions are overwhelming the IPS engine.

  • ✗

    diagnose sys top

    Why it's wrong here

    diagnose sys top displays a list of processes and their CPU/memory usage, not individual sessions or bandwidth. It would show that ipsengine is consuming CPU but would not identify which traffic sessions are causing the load. To see top sessions by bandwidth, a different command is needed.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.