An administrator is troubleshooting why a FortiGate is not applying the expected application control profile to traffic from a specific subnet. The administrator wants to verify which application signature is matching a live session in real time. Which CLI command should be used to display the application name and category for active sessions?
This command lists all active sessions and includes the application name and category if application control is inspecting the session. It provides real-time visibility into which application signature matched, allowing the administrator to confirm whether the correct profile is applied. It is the standard tool for session-level troubleshooting on FortiGate.
Why this answer
The administrator needs to see the application name and category for active sessions. The diagnose sys session list command provides detailed session information, including application identification when application control is enabled. This allows real-time verification of which signature is matching, confirming whether the correct application control profile is applied to the subnet's traffic.
Exam trap
The trap here is assuming that any diagnose debug command will show application identification, when only session listing commands provide that level of detail.