Courseiva

NSE7 · domain

Troubleshooting and Diagnostics

This domain covers diagnosing FortiGate issues using FortiOS CLI tools: real-time process monitoring, session and debug output, SSL VPN troubleshooting, and HA failover behavior. Questions present a symptom and ask for the likely cause or the correct command, so you must recognize what each diagnostic tool reveals and interpret its output accurately.

112 questions29 easy50 medium33 hard

Focused practice

Practice Troubleshooting and Diagnostics questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Troubleshooting and Diagnostics

Be able to pick the right FortiOS diagnostic command for a symptom and read its output correctly. The most important thing: know which sessions survive HA failover and how session synchronization determines that.

Using 'diagnose sys top' for real-time CPU and memory process monitoring

Interpreting 'diagnose debug application sslvpn -1' output for SSL VPN tunnel failures

Counting sessions with 'diagnose sys session stat' and 'get system session status'

Understanding why TCP sessions drop after HA failover due to session synchronization

Watch out for

Common Troubleshooting and Diagnostics exam traps

  • ▸Assuming all sessions survive HA failover; only sessions synchronized to the secondary are preserved, so unsynchronized TCP sessions drop.
  • ▸Confusing 'diagnose debug application sslvpn' with general debug commands; it targets SSL VPN daemon messages, not all VPN traffic.
  • ▸Using 'get system performance status' for per-process detail when 'diagnose sys top' is needed for real-time process-level CPU and memory.

Question index

All Troubleshooting and Diagnostics questions (112)

Click any question to see the full explanation, or start a practice session above.

1

An administrator is troubleshooting why a FortiGate is not applying the expected application control profile to traffic from a specific subnet. The administrator wants to verify which application signature is matching a live session in real time. Which CLI command should be used to display the application name and category for active sessions?

Medium
2

A FortiGate is configured to send logs to FortiAnalyzer. The administrator notices that logs are not appearing on FortiAnalyzer. Running 'diagnose log device show' shows 'connected=no'. What is the most likely cause?

Medium
3

An administrator is troubleshooting an SD-WAN scenario where traffic from a branch office to a critical SaaS application is experiencing high latency. The SD-WAN rule uses the best quality SLA strategy. The administrator runs 'diagnose sys sdwan neighbor' and sees that both WAN links have SLA compliance above 90%. However, traffic still uses the slower link. The administrator then runs 'diagnose sys sdwan health-check list' and notices that the health-check server IP is different from the SaaS application's server IP. What is the MOST likely reason the traffic is not using the best-performing link?

Hard
4

A network administrator runs 'get system ha status' on a FortiGate HA cluster and sees that only one unit shows as primary. The secondary unit shows as 'standalone' with no HA peer detected. What is the MOST likely cause of this issue?

Easy
5

An administrator configures BGP route advertisement but the routes are not being sent to the neighbor. The BGP session is established. What is the MOST likely cause?

Medium
6

An administrator is troubleshooting high CPU usage on a FortiGate. The administrator suspects that a specific process is causing the issue. Which TWO commands should the administrator use to identify the top CPU-consuming processes? (Choose two.)

Medium
7

An administrator needs to monitor the FortiGate's CPU usage in real-time from the CLI. Which command should be used?

Easy
8

An administrator needs to verify if a FortiGate is receiving BGP routes from a peer. Which command should the admin run to see the BGP routing table?

Easy
9

A FortiGate administrator is investigating a slow network performance issue. The administrator suspects that session table limits are being reached. Which TWO metrics should be monitored to confirm this? (Choose two.)

Hard
10

An administrator is troubleshooting an IPsec VPN tunnel that establishes phase 1 but fails to establish phase 2. The phase 2 configuration shows 'set proposal aes128-sha256' on both sides. Which TWO configuration items should the administrator verify?

Medium
11

A FortiGate administrator wants to monitor performance thresholds to be alerted when the firewall is under heavy load. Which THREE metrics can be monitored using the built-in performance monitoring features (e.g., 'diagnose sys top' or SNMP)?

Easy
12

An administrator is troubleshooting an IPsec VPN Phase 2 negotiation failure. The debug shows 'no matching phase 2 proposal' from the remote peer. Which TWO of the following are likely causes? (Choose two.)

Hard
13

A network administrator is troubleshooting a split-brain scenario in an HA cluster. Which TWO conditions can cause split-brain? (Choose two.)

Medium
14

An admin is troubleshooting an IPsec VPN tunnel that is failing phase 2. The IKE debug shows 'no matching proposal'. Which TWO settings should the admin verify on both sides? (Choose two.)

Medium
15

A FortiGate administrator is troubleshooting a VPN tunnel that connects to a remote site. The tunnel is up, but traffic is not passing. The administrator checks the Phase 2 settings and sees that the local and remote subnets are correctly defined. What is the next step to diagnose the issue?

Medium
16

A network administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The remote gateway logs show a proposal mismatch. On FortiGate, the administrator runs 'diagnose vpn ike config' and sees 'proposal: aes128-sha1, aes256-sha256'. The remote side expects 'aes256-sha1'. What is the most likely cause?

Medium
17

An administrator wants to monitor the session count on a FortiGate in real time. Which CLI command provides this information?

Easy
18

An administrator applies the above policy but users from 10.0.1.0/24 cannot access web servers at 10.0.2.0/24. However, they can ping the servers. What is the most likely cause?

Easy
19

An administrator is investigating a security incident and needs to view raw logs from a FortiAnalyzer for a specific time range. The administrator wants to ensure the logs are not aggregated or summarized. Which type of log view should be used?

Hard
20

An administrator is troubleshooting an HA cluster (active-passive) where both units show 'primary' in 'get system ha status'. The cluster is not synchronizing configurations. What is the MOST likely cause?

Hard
21

A FortiGate VPN tunnel shows 'phase1 negotiation failed' in the logs. The remote gateway is a third-party device. The debug command 'diagnose vpn ike config' shows mismatched proposals. Which setting is MOST likely incorrect on the FortiGate?

Medium
22

A FortiGate administrator needs to verify that the firewall is correctly identifying and logging a specific application, 'Facebook', that is being used by internal users. The administrator has already configured an application control profile with logging enabled for Facebook. Which CLI command should the administrator use to view the application control logs in real-time?

Easy
23

A FortiGate administrator is troubleshooting high CPU usage. The administrator runs 'diagnose sys top' and sees that the 'ipsengine' process is consuming a large amount of CPU. Which action should the administrator take to reduce the CPU usage while maintaining security?

Medium
24

Which FortiGate command is used to view the current CPU usage of individual processes in real time?

Easy
25

A FortiGate administrator needs to identify which process is consuming the most memory. Which command should be used?

Easy
26

An administrator is troubleshooting a BGP session that is not establishing between two FortiGates. The administrator has verified that the neighbor IP is reachable. Which TWO commands should be used to further diagnose the issue? (Choose two.)

Medium
27

A FortiGate administrator is troubleshooting an issue where users are unable to access a web server behind the FortiGate. The web server is on the DMZ network, and users are on the internal network. The firewall policy from internal to DMZ is configured to allow HTTP and HTTPS. The administrator runs 'diagnose debug flow' and sees that packets are being dropped with the message 'iprope_in_check() check failed, drop'. Which two actions should the administrator take to resolve this issue? (Choose two.)

Medium
28

An administrator configures an ALG for SIP traffic but notices that some SIP calls are failing. The admin suspects the ALG is modifying SIP headers incorrectly. Which debug command can help verify the ALG's actions on SIP packets?

Hard
29

A network administrator is troubleshooting why a FortiGate does not appear to be enforcing a newly configured application control profile. The policy is applied to traffic from the internal network to the internet. The administrator runs 'diagnose sys session list' and sees that sessions are being created, but the application control profile is not listed in the session details. Which action should the administrator take to verify that the application control profile is being applied?

Medium
30

Which of the following is a valid command to check the status of all BGP neighbors on a FortiGate?

Easy
31

You are troubleshooting a VPN phase 2 negotiation failure. The logs show 'no proposal chosen'. What is the MOST likely cause?

Hard
32

During a failover test in an active-passive HA cluster, the administrator notices that the secondary unit does not take over the primary role after a link failure on the primary. The 'get system ha status' shows both units in 'standalone' mode. What is the MOST likely cause?

Medium
33

A FortiGate is configured with a firewall policy that has a URL filter profile. Users report that access to a specific website is blocked, but the administrator wants to verify which URL filter category matched the request. The administrator runs 'diagnose debug application urlfilter -1' in the CLI. However, no output appears. What is the MOST likely reason for the lack of output?

Medium
34

A FortiGate administrator wants to see the current number of active sessions. Which command provides this information?

Easy
35

A network administrator is troubleshooting a FortiGate HA cluster in active-passive mode. The administrator notices that the secondary unit is not receiving heartbeat packets from the primary unit, and the cluster has split. The administrator runs 'diagnose sys ha status' on both units and sees that the primary unit shows the secondary as 'not connected', while the secondary unit shows the primary as 'not connected'. The administrator verifies that the heartbeat interfaces are correctly configured and physically connected. What is the MOST likely cause of the split?

Hard
36

A site-to-site IPsec VPN tunnel is failing. The administrator runs 'diagnose vpn ike config' and sees that phase 1 parameters are correct. However, phase 2 negotiation fails with 'no proposal chosen'. What is the MOST likely cause?

Medium
37

An administrator wants to troubleshoot why specific traffic is not matching a configured firewall policy. Which debug command should be used?

Medium
38

An administrator runs 'diagnose debug application fnbam -1' and sees messages like 'LB_SELECT: selected server 10.0.0.2:80' but the client connection fails. The FortiGate is configured with server load balancing. What could be the issue?

Hard
39

A FortiGate is configured with multiple BGP peers. One of the peers is not receiving the expected routes. The administrator runs 'get router info bgp neighbors <IP>' and sees that the 'State/PfxRcd' field is 'Active'. What does this indicate?

Medium
40

An administrator notices high CPU usage on a FortiGate. To identify which process is consuming the most CPU, which command should be used?

Medium
41

A FortiGate is configured with a firewall policy that applies an application control profile blocking social media. Users report that they can still access Facebook. The administrator verifies that the policy is correctly matching the traffic and that the application control profile is applied. Which CLI command should the administrator use to verify whether the application control is correctly identifying the traffic?

Medium
42

A FortiGate is configured with a VIP for an internal web server. Users report that the web server is unreachable from the internet, but it is accessible from the internal network. The administrator runs 'diagnose debug flow' with filters for the public IP and sees that the traffic reaches the FortiGate but is dropped with the message 'iprope_in_check() check failed, drop'. What is the MOST likely cause?

Hard
43

An administrator is troubleshooting a FortiGate HA cluster that is experiencing frequent failovers. The administrator wants to verify the HA status and identify potential issues. Which TWO commands should the administrator use to gather relevant information? (Choose two.)

Medium
44

An administrator wants to see the current number of active sessions on a FortiGate. Which command should the admin use?

Easy
45

A FortiGate is configured with an explicit web proxy on port 8080. Users report that some websites load slowly while others fail to load at all. The administrator runs 'diagnose debug application wad 8' and sees messages about 'proxy worker' and 'connection failed'. Which command should the administrator use to view the current proxy sessions in real time?

Medium
46

Drag and drop the steps to perform a firmware upgrade on a FortiGate device into the correct order.

Medium
47

An HA cluster of two FortiGates is experiencing split-brain. After investigation, you find that the heartbeat link is down on the primary unit. Which action will resolve the split-brain condition?

Hard
48

An SD-WAN rule is configured to steer traffic based on SLA metrics. The administrator notices that traffic is not using the expected member interface even though the SLA is meeting thresholds. What should the administrator check FIRST?

Medium
49

An administrator is troubleshooting an HA cluster where both units show as primary after a link failure. What is the most likely cause of this split-brain scenario?

Easy
50

An administrator configures SD-WAN with multiple members. The SD-WAN rule uses the 'latency' strategy. The administrator notices that traffic is not switching to the best-performing member even when latency exceeds the threshold. What could be the issue?

Hard
51

An administrator is troubleshooting a scenario where traffic from VLAN 100 to a server at 10.1.2.100 is being blocked. The FortiGate has an active security policy allowing the traffic and the routing table shows a correct route. Which TWO diagnostic commands should the administrator run to identify the cause of the blockage?

Medium
52

A FortiGate administrator wants to check if the device is experiencing high CPU usage due to a specific process. Which command should they use to display real-time process CPU usage?

Easy
53

When troubleshooting an IPsec VPN phase 1 negotiation failure, which debug command should the administrator run to see detailed IKE negotiation messages?

Medium
54

Based on the exhibit, what can be concluded about the session?

Hard
55

An administrator is troubleshooting a FortiGate that is experiencing high CPU usage. The administrator runs 'diagnose sys top' and observes that the 'ipsengine' process is consuming a large amount of CPU. The administrator suspects that a specific IPS signature is causing the issue. Which command should the administrator use to identify which IPS signature is triggering the high CPU usage?

Hard
56

A FortiGate in an HA cluster is experiencing intermittent session synchronization failures. The administrator runs 'diagnose sys ha dump sync-status' and sees that sessions are not being synchronized properly. Which TWO potential causes should the administrator investigate?

Medium
57

You are troubleshooting an SD-WAN rule where traffic is not matching the expected SLA. The FortiGate shows 'SLA mismatch' in logs. What is the MOST likely cause?

Medium
58

An administrator needs to verify that a FortiGate is correctly matching a firewall policy for traffic from 192.168.1.0/24 to 10.0.0.0/8. Which command provides a list of policies that match a given source and destination?

Easy
59

Based on the debug flow output, what is the reason the packet is dropped?

Hard
60

An HA cluster of two FortiGates is experiencing split-brain. Which command should the administrator use to check the current HA status and identify which unit is the primary?

Easy
61

A FortiGate admin notices that HTTPS traffic to a web server is not being scanned by the antivirus profile applied to the firewall policy. The admin confirms the policy is correct and antivirus is enabled. What is the MOST likely reason the traffic is not being scanned?

Medium
62

A FortiGate administrator is troubleshooting a policy that is supposed to allow HTTP traffic from an internal subnet to a web server. Users report that they cannot access the web server. The administrator runs 'diagnose debug flow' and sees that the traffic is being denied by policy 0. What is the most likely cause?

Easy
63

An administrator needs to check the current CPU and memory usage of a FortiGate to determine if resource exhaustion is causing network delays. Which CLI command provides a real-time, top-like view of processes and their resource consumption?

Easy
64

A FortiGate administrator is troubleshooting a connectivity issue where users cannot access a web server behind the FortiGate from the internet. The administrator suspects that the virtual IP (VIP) configuration is incorrect. Which two commands should the administrator use to verify the VIP configuration and its associated firewall policy? (Choose two.)

Medium
65

A FortiGate is experiencing high CPU usage. The administrator runs 'diagnose sys top' and sees that the process 'ipsengine' is using the most CPU. What is the most likely cause?

Easy
66

An administrator needs to monitor FortiGate session count and CPU usage over time using FortiAnalyzer. Which log type should be configured for this?

Easy
67

An HA cluster (active-passive) is configured. The administrator wants to perform a failover test without causing service disruption. Which command should be used?

Medium
68

A FortiGate administrator runs 'diagnose debug application sslvpn -1' and sees repeated messages: 'SSL VPN tunnel error: no response from client'. What is the most likely cause?

Medium
69

Which TWO actions are appropriate when troubleshooting a slow network connection through a FortiGate?

Medium
70

A customer reports intermittent connectivity issues between two internal subnets separated by a FortiGate firewall. The traffic is allowed by the policy, but users experience timeouts during peak hours. Which troubleshooting step should you take first?

Medium
71

A FortiGate is configured with a VIP (virtual IP) for an internal web server. Users report that the web server is unreachable from the internet, but it works from the internal network. The administrator runs 'diagnose sniffer packet any "host 203.0.113.10 and port 80" 4' and sees incoming packets on the wan1 interface but no outgoing packets on the internal interface. What is the MOST likely cause?

Hard
72

A BGP peering between two FortiGates is not establishing. The administrator runs 'get router info bgp neighbor' and sees that the neighbor state is 'Idle' and the BGP configuration appears correct. What should the administrator check next?

Hard
73

During a failover test in an HA cluster, the primary FortiGate fails over to the secondary. After failover, some existing TCP sessions are dropped. What is the MOST likely reason?

Medium
74

A FortiGate is configured with a VIP (virtual IP) to publish an internal web server to the internet. External users report that they cannot access the web server, but internal users can access it using its private IP. The administrator runs 'diagnose debug flow' and sees that traffic from external users is being dropped with the message 'iprope_in_check() check failed, drop'. What is the most likely cause?

Hard
75

An administrator notices that a FortiGate's CPU is consistently high, and the performance dashboard shows the 'ipsengine' process consuming most CPU. The administrator suspects a specific traffic pattern is overwhelming the IPS engine. Which CLI command should be used to identify the top sessions by bandwidth that may be triggering the IPS engine?

Medium
76

A FortiGate is configured with an IPsec VPN tunnel to a remote peer. The tunnel is up, but traffic is not passing through it. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established. The administrator then runs 'diagnose debug flow' and sees that traffic is being dropped with the message 'iprope_in_check() check failed, drop'. What is the MOST likely cause of the drop?

Hard
77

A FortiGate administrator is investigating a slow network issue. The 'diagnose sys session stat' shows a high number of sessions. Which THREE commands can help identify the source of the high session count?

Hard
78

A FortiGate is configured with a VIP (virtual IP) for an internal web server at 10.0.0.10, mapping to public IP 203.0.113.5. External users report that they cannot access the web server, but internal users can access it using the private IP. The administrator runs 'diagnose debug flow filter addr 203.0.113.5' and 'diagnose debug flow show function-name enable' and sees the following output: 'id=20085 trace_id=1 func=print_pkt_detail line=4793 msg="vd-root:0 received a packet(proto=6, 203.0.113.5:443->198.51.100.10:54321) from port1. flag [S], seq 123456, ack 0, win 8192"' followed by 'id=20085 trace_id=1 func=init_ip_session_common line=4970 msg="allocate a new session-00000123"' and then 'id=20085 trace_id=1 func=vf_ip_route_input_common line=2580 msg="find a route: flag=04000000 gw-10.0.0.10 via port2"'. No further output appears. What is the MOST likely cause of the issue?

Hard
79

An administrator is troubleshooting why a FortiGate is dropping traffic from a specific source IP (10.1.1.100). The administrator wants to see real-time per-packet details including the reason for drops. Which CLI command should the administrator use?

Medium
80

A FortiGate admin notices that sessions to a particular server are not being logged in FortiAnalyzer. The firewall policy has logging enabled. What is the MOST likely reason?

Medium
81

An administrator wants to see the current sessions for a specific source IP address 192.168.1.10. Which CLI command should be used?

Easy
82

An administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The Phase 1 status shows 'init' and the debug output indicates 'no suitable proposal found'. The remote peer is a third-party VPN device. Which of the following is the MOST likely cause?

Hard
83

An administrator is investigating a security incident and needs to determine which firewall policy allowed a specific malicious traffic flow. The traffic is no longer active. Which FortiAnalyzer log type should the admin query?

Hard
84

An administrator wants to monitor CPU usage of specific processes on a FortiGate. Which command should be used?

Easy
85

A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The VPN tunnel is up, but traffic is not passing. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established with the correct selectors. Which two commands should the administrator use to further troubleshoot why traffic is not passing through the tunnel? (Choose two.)

Hard
86

An administrator runs 'diagnose debug application ipsmonitor -1' and sees repeated messages: 'IPS engine restarting'. What is the MOST likely cause of this behavior?

Medium
87

A FortiGate administrator is investigating a security incident and needs to identify which user initiated a specific outbound connection to a malicious IP address. The company uses FSSO for authentication. Which THREE pieces of information from FortiAnalyzer logs would be MOST useful? (Choose three.)

Medium
88

During a BGP troubleshooting session, an administrator sees that the BGP neighbor state is 'Active'. Which three conditions could cause this state? (Choose THREE.)

Hard
89

A FortiGate administrator wants to verify whether a specific session is being offloaded to the NP6 processor. Which CLI command should the administrator use?

Easy
90

A FortiGate is receiving BGP routes from a neighbor but not advertising them to other peers. The administrator runs 'get router info bgp network' and sees the routes are in the BGP table but not advertised. What is the most likely cause?

Medium
91

An administrator is troubleshooting a FortiGate that is experiencing high CPU usage. The administrator wants to identify which processes are consuming the most CPU. Which command should be used?

Easy
92

You receive an alert that FortiAnalyzer log disk usage is at 95%. Which action should you take to immediately free up space without losing important logs?

Easy
93

An administrator wants to verify that a BGP route is being advertised to a neighbor. Which command displays the routes that FortiGate is advertising to a specific BGP neighbor?

Easy
94

A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The administrator notices that the VPN tunnel is up, but traffic is not passing through it. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is up with the correct selectors. Which command should the administrator use next to verify whether traffic is being encrypted and sent out?

Medium
95

A FortiGate is configured with a site-to-site IPsec VPN to a remote office. Users at the remote office report that they cannot access resources at the main office. The administrator checks the VPN status and sees that the tunnel is up. Which two actions should the administrator take to troubleshoot the issue? (Choose two.)

Hard
96

An administrator is troubleshooting a FortiGate that is experiencing high CPU usage. The administrator runs 'diagnose sys top' and sees that the 'ipsengine' process is consuming a large amount of CPU. Which two actions should the administrator take to further diagnose and potentially resolve the issue? (Choose two.)

Hard
97

A FortiGate administrator uses FortiAnalyzer for log analysis and wants to identify all sessions that were blocked by a specific firewall policy ID 10. Which log filter should be applied?

Medium
98

You run 'diagnose sys session filter dport 443' and see sessions with a duration of 7200 seconds and expire time of 3600 seconds. What does this indicate?

Medium
99

An administrator is troubleshooting a FortiGate that is dropping traffic from a specific VLAN. The administrator runs 'diagnose debug flow' with a filter for the VLAN's subnet and sees the trace terminate with the message 'iprope_in_check() check failed, drop'. What is the MOST likely cause?

Hard
100

A FortiGate is configured with SD-WAN and multiple members. The administrator notices that traffic to a critical application is consistently routed over a low-quality link, even though a better link is available. The SD-WAN rule uses the 'Best Quality' strategy with a performance SLA. What is the most likely reason?

Medium
101

An administrator is troubleshooting a FortiGate that is experiencing intermittent packet loss for traffic passing through an IPsec VPN tunnel. The administrator wants to capture packets on the VPN interface to analyze the issue. Which command should the administrator use to capture packets on the IPsec tunnel interface named 'vpn1'?

Hard
102

A network admin runs 'diagnose sys top' on a FortiGate and sees that the process 'httpsd' is consistently using 95% CPU. Which of the following actions is MOST appropriate to troubleshoot this issue?

Medium
103

An administrator wants to monitor real-time CPU usage per process on a FortiGate. Which command should be used?

Easy
104

An administrator is configuring SD-WAN and wants to ensure that voice traffic uses the lowest latency link. Which two configurations are required to achieve this? (Choose TWO.)

Medium
105

A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The administrator notices that the VPN tunnel is up, but traffic is not passing through it. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established with the correct selectors. The administrator then runs 'diagnose debug flow filter addr 10.1.1.1' (the remote subnet) and 'diagnose debug flow show function-name enable', and observes the following output: 'id=20085 trace_id=1 func=print_pkt_detail line=4793 msg="vd-root:0 received a packet(proto=6, 10.1.1.1:80->192.168.1.100:12345) from port1. flag [S], seq 123456, ack 0, win 8192"' followed by 'id=20085 trace_id=1 func=init_ip_session_common line=4970 msg="allocate a new session-00000123"' and then 'id=20085 trace_id=1 func=vf_ip_route_input_common line=2580 msg="find a route: flag=04000000 gw-192.168.1.1 via port2"'. No further output appears. What is the MOST likely cause of the issue?

Hard
106

A FortiGate cluster (A-P) has a session that is not synchronizing to the secondary unit. The administrator runs 'diagnose sys ha session-sync status' and sees that the session count is different between primary and secondary. Which is the most likely cause?

Hard
107

A FortiGate administrator wants to quickly identify which process is consuming the most CPU on the device. Which CLI command should be used?

Easy
108

An administrator is configuring a FortiGate to inspect SMTP traffic for spam and viruses. The traffic must be decrypted to inspect the content. Which THREE elements are required for this configuration? (Choose three.)

Medium
109

An administrator runs 'diagnose debug application sslvpn -1' and sees repeated 'SSL_ERROR_SSL: error:1417C0C7:SSL routines:tls_process_client_certificate:peer did not return a certificate'. The SSL-VPN is configured to require client certificates. What is the cause?

Hard
110

Which two commands display the current session count on a FortiGate?

Easy
111

An administrator is troubleshooting an issue where a FortiGate is not forwarding traffic between two internal subnets. The administrator runs 'diagnose debug flow' and sees that packets are entering the FortiGate but are dropped with the message 'reverse path check fail, drop'. What is the MOST likely cause?

Hard
112

When troubleshooting an IPsec VPN phase 1 failure, you run 'diagnose vpn ike config' and see that the remote gateway IP address is incorrect. Which command is used to correct the peer IP configuration?

Medium

Frequently asked questions

What does the Troubleshooting and Diagnostics domain cover on the NSE7 exam?
Be able to pick the right FortiOS diagnostic command for a symptom and read its output correctly. The most important thing: know which sessions survive HA failover and how session synchronization determines that.
How many questions are in this domain?
This page lists all 112 Troubleshooting and Diagnostics questions in the NSE7 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Troubleshooting and Diagnostics questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
fortinet-nse7 FORTINET-NSE7 nse7 troubleshooting Practice Questions