Courseiva

CCNA Nse7 Troubleshooting Questions

37 of 112 questions · Page 2/2 · Nse7 Troubleshooting topic · Answers revealed

76
MCQhard

A FortiGate is configured with an IPsec VPN tunnel to a remote peer. The tunnel is up, but traffic is not passing through it. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established. The administrator then runs 'diagnose debug flow' and sees that traffic is being dropped with the message 'iprope_in_check() check failed, drop'. What is the MOST likely cause of the drop?

A.The VPN tunnel is using the wrong pre-shared key.
B.The firewall policy for the VPN traffic is missing or incorrect.
C.The IPsec phase2 selectors do not match the traffic being sent.
D.The routing table does not have a route to the remote subnet.
AnswerB

The message 'iprope_in_check() check failed, drop' indicates that the traffic was dropped by the firewall policy check. This typically means that no firewall policy matches the traffic, or the matching policy has an action of deny. In the context of an IPsec VPN, traffic arriving from the tunnel must be matched by a policy that allows it. If the policy is missing or misconfigured, the packet is dropped. This is the most likely cause.

Why this answer

The error 'iprope_in_check() check failed, drop' is generated by the firewall policy check. It means that the packet did not match any allow policy or matched a deny policy. In an IPsec VPN scenario, this often happens when the policy allowing traffic from the VPN tunnel is missing or incorrectly configured.

The administrator should verify that a policy exists with the correct incoming interface, source, destination, and service.

Exam trap

The trap here is focusing on IPsec configuration when the error clearly points to a firewall policy issue, leading to unnecessary troubleshooting of the tunnel itself.

77
Multi-Selecthard

A FortiGate administrator is investigating a slow network issue. The 'diagnose sys session stat' shows a high number of sessions. Which THREE commands can help identify the source of the high session count?

Select 3 answers
A.diagnose sys session list | grep <policy_id>
B.diagnose sys session filter src <IP>
C.diagnose sys session top-talkers
D.diagnose sys session stat
E.diagnose netlink interface list
AnswersA, B, C

Counts sessions per policy to see which policy is most used.

Why this answer

'diagnose sys session list | grep <policy_id>' filters the session list to show only sessions matching a specific firewall policy ID. This allows the administrator to identify which policy is handling the most sessions, helping to pinpoint the source of high session counts by correlating traffic patterns with policy usage.

Exam trap

The trap here is that candidates may think 'diagnose sys session stat' (Option D) provides source-level detail, but it only shows aggregate counters, not per-source or per-policy breakdowns, making it useless for identifying the specific source of high session counts.

78
MCQhard

A FortiGate is configured with a VIP (virtual IP) for an internal web server at 10.0.0.10, mapping to public IP 203.0.113.5. External users report that they cannot access the web server, but internal users can access it using the private IP. The administrator runs 'diagnose debug flow filter addr 203.0.113.5' and 'diagnose debug flow show function-name enable' and sees the following output: 'id=20085 trace_id=1 func=print_pkt_detail line=4793 msg="vd-root:0 received a packet(proto=6, 203.0.113.5:443->198.51.100.10:54321) from port1. flag [S], seq 123456, ack 0, win 8192"' followed by 'id=20085 trace_id=1 func=init_ip_session_common line=4970 msg="allocate a new session-00000123"' and then 'id=20085 trace_id=1 func=vf_ip_route_input_common line=2580 msg="find a route: flag=04000000 gw-10.0.0.10 via port2"'. No further output appears. What is the MOST likely cause of the issue?

A.The VIP is configured with port forwarding, but the external port does not match the internal port.
B.The VIP is not configured with the correct external IP address.
C.The internal web server is not responding to the SYN packet, or the return traffic is being dropped by the FortiGate.
D.The firewall policy that allows traffic from the external interface to the VIP does not exist or is incorrect.
AnswerC

The debug flow output ends after the route lookup, meaning the FortiGate forwarded the packet to the internal server but did not receive a response. This indicates that either the server is not responding (e.g., service down, firewall on server) or the return traffic is being dropped by the FortiGate. Common causes include asymmetric routing, missing return policy, or the server's default gateway not pointing to the FortiGate. The administrator should check the server's status and the FortiGate's session table for return traffic.

Why this answer

The debug flow output indicates that the FortiGate received the SYN packet, allocated a session, and performed a route lookup to forward the packet to the internal server. However, no further output appears, meaning the FortiGate did not receive a SYN-ACK from the server. This points to either the server not responding or the return traffic being blocked.

The administrator should verify the server's availability and check for asymmetric routing or missing return policies that could drop the response.

Exam trap

The trap here is assuming that a missing firewall policy is the cause, but the debug flow shows a session was allocated, indicating the policy likely matched.

79
MCQmedium

An administrator is troubleshooting why a FortiGate is dropping traffic from a specific source IP (10.1.1.100). The administrator wants to see real-time per-packet details including the reason for drops. Which CLI command should the administrator use?

A.diagnose debug enable
B.diagnose debug flow filter addr 10.1.1.100
C.diagnose debug flow filter addr 10.1.1.100 && diagnose debug flow trace start 100 && diagnose debug enable
D.diagnose debug flow trace start 100
AnswerC

This sequence correctly sets a filter for the source IP, starts a flow trace for 100 packets, and enables debug output. The 'diagnose debug flow' commands provide detailed per-packet information including the reason for drops, which is exactly what the administrator needs to troubleshoot the issue.

Why this answer

To troubleshoot dropped traffic from a specific source IP, the administrator must set a filter, start the flow trace, and enable debug output. The combination of 'diagnose debug flow filter addr', 'diagnose debug flow trace start', and 'diagnose debug enable' provides real-time per-packet details including drop reasons, allowing effective diagnosis.

Exam trap

The trap here is assuming that setting the filter alone or enabling debug globally is sufficient, when in fact all three steps are required to capture and display the relevant flow information.

80
MCQmedium

A FortiGate admin notices that sessions to a particular server are not being logged in FortiAnalyzer. The firewall policy has logging enabled. What is the MOST likely reason?

A.The FortiAnalyzer's device registration is incorrect
B.The log queue on FortiGate is full
C.The FortiGate is not configured to send logs to FortiAnalyzer
D.The FortiAnalyzer is out of disk space
AnswerC

Without a configured log-forwarding destination, the FortiGate generates local traffic logs but never transmits them, so FortiAnalyzer receives nothing regardless of the policy's logging setting. The stem's constraint is that policy logging is already enabled, which rules out policy-level causes and points to the missing FortiAnalyzer output configuration.

Why this answer

The most likely reason is that the FortiGate is not configured to send logs to FortiAnalyzer. Even if the firewall policy has logging enabled, logs are only generated locally on the FortiGate; they must be explicitly forwarded to FortiAnalyzer via the 'config log fortianalyzer setting' CLI or GUI configuration. Without this configuration, no logs reach FortiAnalyzer regardless of policy settings.

Exam trap

The trap here is that candidates assume enabling logging on a firewall policy automatically sends logs to FortiAnalyzer, but FortiGate requires an explicit log forwarding configuration to direct logs to an external analyzer.

How to eliminate wrong answers

Option A is wrong because incorrect device registration on FortiAnalyzer would prevent log reception or cause authentication failures, but the question states sessions are not being logged at all, which points to a missing log forwarding configuration rather than a registration mismatch. Option B is wrong because a full log queue on FortiGate would cause log loss or backpressure, but it would not prevent all sessions from being logged; some logs would still be sent until the queue is exhausted, and the admin would typically see queue warnings. Option D is wrong because if FortiAnalyzer is out of disk space, it would stop accepting new logs and generate disk-full alerts, but the FortiGate would still attempt to send logs and the issue would be on the analyzer side, not a complete absence of logging.

81
MCQeasy

An administrator wants to see the current sessions for a specific source IP address 192.168.1.10. Which CLI command should be used?

A.diagnose sys session filter src 192.168.1.10; diagnose sys session list
B.get system session list src 192.168.1.10
C.diagnose debug flow src-addr 192.168.1.10
D.execute session list source 192.168.1.10
AnswerA

Setting a session filter on the source address restricts the session table output to entries matching 192.168.1.10, satisfying the requirement to view only that host's current sessions. Running `diagnose sys session list` afterwards dumps the filtered table, avoiding the noise of every active session on the FortiGate.

Why this answer

The `diagnose sys session filter src` command sets a filter for the source IP address, and `diagnose sys session list` then displays only the sessions matching that filter. This two-step process is the standard FortiGate CLI method for viewing active sessions for a specific source IP, as it leverages the session table directly without triggering debug overhead.

Exam trap

The trap here is that candidates confuse the `diagnose` command category (used for diagnostics and session inspection) with `get` or `execute` commands, or mistakenly think `diagnose debug flow` is appropriate for listing sessions when it is actually a real-time debug tool that can disrupt production traffic.

How to eliminate wrong answers

Option B is wrong because `get system session list` is not a valid FortiGate command; the correct command for listing sessions is `diagnose sys session list`, and `get` commands are used for configuration objects, not session diagnostics. Option C is wrong because `diagnose debug flow` is used for real-time packet flow debugging with detailed logging, not for listing existing sessions; it would generate excessive output and is not designed to show the current session table. Option D is wrong because `execute session list` is not a valid FortiGate command; the `execute` command category is for administrative actions like backups or reboots, not for session inspection.

82
MCQhard

An administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The Phase 1 status shows 'init' and the debug output indicates 'no suitable proposal found'. The remote peer is a third-party VPN device. Which of the following is the MOST likely cause?

A.The pre-shared key is incorrect on one side
B.The remote peer's IP address is not reachable
C.The IKE version or encryption algorithm does not match between the peers
D.The firewall policy allowing the VPN traffic is missing
AnswerC

'No suitable proposal found' during Phase 1 means the peers could not agree on an IKE version, encryption, hash or DH group. With a third-party device, mismatched IKEv1/IKEv2 or algorithm settings are the most likely cause of the stuck init state.

Why this answer

The 'no suitable proposal found' error in Phase 1 indicates that the IKE proposal parameters (such as encryption algorithm, hash algorithm, Diffie-Hellman group, or IKE version) do not match between the FortiGate and the third-party peer. Since the status is 'init', the peers have exchanged initial packets but cannot agree on a common proposal, which is a classic proposal mismatch issue. A pre-shared key mismatch would typically cause an authentication failure later in Phase 1, not a 'no suitable proposal' error.

Exam trap

The trap here is that candidates often confuse 'no suitable proposal' with a pre-shared key mismatch, but the error occurs earlier in the IKE exchange before authentication begins, so it must be a proposal parameter mismatch.

How to eliminate wrong answers

Option A is wrong because a pre-shared key mismatch would result in an authentication failure (e.g., 'invalid cookie' or 'authentication failed') after the proposal is accepted, not a 'no suitable proposal found' error. Option B is wrong because if the remote peer's IP address were unreachable, the Phase 1 status would show 'down' or the debug would show 'no response' or 'timeout', not an active exchange with a proposal rejection. Option D is wrong because a missing firewall policy allowing VPN traffic would prevent the IKE packets from being forwarded, resulting in no response or a timeout, not a proposal negotiation failure.

83
MCQhard

An administrator is investigating a security incident and needs to determine which firewall policy allowed a specific malicious traffic flow. The traffic is no longer active. Which FortiAnalyzer log type should the admin query?

A.Event logs
B.Security logs
C.Traffic logs
D.Audit logs
AnswerC

Traffic logs record each session with the matching firewall policy ID, source, destination, and action, so historical malicious flows can be traced to the policy that permitted them. This satisfies the requirement to identify the allowing policy after the traffic ended.

Why this answer

Traffic logs record every session that passes through the FortiGate, including the source/destination IPs, ports, policy ID, and action taken. Since the traffic is no longer active, the administrator must query historical traffic logs in FortiAnalyzer to identify which firewall policy permitted the malicious flow. Event logs, security logs, and audit logs do not contain the per-session policy mapping needed for this forensic analysis.

Exam trap

The trap here is that candidates confuse 'security logs' (which log threat detections) with 'traffic logs' (which log all permitted sessions), mistakenly thinking that a security event log would contain the policy ID that allowed the malicious flow, when in fact traffic logs are the only source for historical policy-to-session mapping.

How to eliminate wrong answers

Option A is wrong because event logs capture system events (e.g., HA state changes, interface up/down, admin logins) and do not record per-session firewall policy decisions. Option B is wrong because security logs (e.g., IPS, antivirus, web filter) record threat detections but not the specific firewall policy that allowed the traffic; they reference a policy ID only if the traffic was already permitted. Option D is wrong because audit logs track administrative actions (e.g., config changes, CLI commands) and contain no information about individual traffic flows or firewall policy matches.

84
MCQeasy

An administrator wants to monitor CPU usage of specific processes on a FortiGate. Which command should be used?

A.get system performance status
B.diagnose sys top
C.get system performance
D.top
AnswerB

The diagnose sys top command gives a live, per-process view of CPU and memory consumption on the FortiGate, letting the administrator identify which specific processes are consuming CPU. This directly satisfies the requirement to monitor CPU usage of individual processes rather than aggregate system load.

Why this answer

The 'diagnose sys top' command is the correct tool for monitoring CPU usage of specific processes on a FortiGate because it provides a real-time, interactive view of process-level CPU and memory utilization, allowing the administrator to identify which processes are consuming resources. Unlike the other options, this diagnostic command is specifically designed for granular process monitoring in FortiOS.

Exam trap

The trap here is that candidates may confuse the generic Linux 'top' command with FortiOS's 'diagnose sys top', or assume that 'get system performance status' provides process-level detail when it only shows aggregate system metrics.

How to eliminate wrong answers

Option A is wrong because 'get system performance status' displays overall system performance statistics (e.g., CPU, memory, sessions) but does not show per-process CPU usage. Option C is wrong because 'get system performance' is not a valid FortiGate command; the correct command for overall performance is 'get system performance status'. Option D is wrong because 'top' is a standard Linux command that is not available in the FortiGate CLI; FortiOS uses 'diagnose sys top' as its equivalent for process-level monitoring.

85
Multi-Selecthard

A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The VPN tunnel is up, but traffic is not passing. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established with the correct selectors. Which two commands should the administrator use to further troubleshoot why traffic is not passing through the tunnel? (Choose two.)

Select 2 answers
A.diagnose ip router lookup <destination_ip>
B.diagnose vpn tunnel list
C.diagnose firewall iprope list
D.diagnose vpn ike log filter src-addr <remote_gateway>
E.diagnose debug flow filter addr <remote_subnet>
AnswersA, E

This command performs a route lookup for a specific destination IP, showing which route and interface the FortiGate would use. If the route lookup shows the traffic is not being routed into the IPsec tunnel, that explains why traffic is not passing. In this scenario, checking the routing for a destination in the remote subnet can reveal if a more specific route is overriding the VPN route or if the tunnel interface is not in the routing table.

Why this answer

When an IPsec tunnel is up but traffic is not passing, the issue often lies in routing or firewall policies. Using 'diagnose debug flow filter' with the remote subnet allows the administrator to trace packet flow and see where packets are dropped. 'diagnose ip router lookup' verifies that the FortiGate routes traffic into the tunnel. Together, these commands help identify if traffic is being routed incorrectly or blocked by a policy, which are common causes for this scenario.

Exam trap

The trap here is focusing on IKE or tunnel status when the tunnel is already established; the problem is likely in routing or firewall policies affecting data traffic.

86
MCQmedium

An administrator runs 'diagnose debug application ipsmonitor -1' and sees repeated messages: 'IPS engine restarting'. What is the MOST likely cause of this behavior?

A.The FortiGate is overloaded with too many concurrent sessions
B.The IPS engine is running out of memory
C.The firewall policy is configured for flow-based inspection
D.The IPS signatures are outdated and need updating
AnswerB

Repeated 'IPS engine restarting' messages indicate the ipsmonitor process is repeatedly restarting the IPS engine because memory exhaustion triggers a crash-and-restart loop. Insufficient memory prevents the engine from completing initialisation, so it terminates and is relaunched, producing the recurring diagnostic output.

Why this answer

The 'IPS engine restarting' message in the output of 'diagnose debug application ipsmonitor -1' indicates that the IPS engine process is crashing and being automatically restarted by the FortiGate's watchdog. The most common cause of IPS engine crashes is memory exhaustion, as the engine requires a dedicated memory heap to process signatures and sessions; when this heap is depleted, the engine terminates to prevent system instability.

Exam trap

The trap here is that candidates often confuse 'IPS engine restarting' with general system overload or policy misconfiguration, but the specific debug output points directly to a process crash, which is almost always caused by memory exhaustion in the IPS engine heap.

How to eliminate wrong answers

Option A is wrong because an overload of concurrent sessions would typically cause high CPU usage or session table exhaustion, not a specific IPS engine restart; the IPS engine can handle high session counts if memory is sufficient. Option C is wrong because flow-based inspection is a valid inspection mode that uses the IPS engine, but it does not inherently cause engine restarts; the engine restart issue is related to resource exhaustion, not the inspection mode itself. Option D is wrong because outdated IPS signatures do not cause the engine to restart; they may result in missed detections or false positives, but the engine process remains stable unless memory or other critical resources are exhausted.

87
Multi-Selectmedium

A FortiGate administrator is investigating a security incident and needs to identify which user initiated a specific outbound connection to a malicious IP address. The company uses FSSO for authentication. Which THREE pieces of information from FortiAnalyzer logs would be MOST useful? (Choose three.)

Select 3 answers
A.Username from the FortiGate authentication log
B.Destination IP address
C.Event type (e.g., traffic, event, attack)
D.Source IP address of the session
E.Timestamp of the session
AnswersA, D, E

Links the session to the authenticated user.

Why this answer

FSSO (Fortinet Single Sign-On) maps network sessions to Active Directory usernames via the FortiGate authentication log. When investigating which user initiated an outbound connection to a malicious IP, the username from this log directly ties the session to a specific identity, enabling attribution beyond just IP addresses.

Exam trap

The trap here is that candidates often select 'Destination IP address' thinking it helps identify the user, but it only identifies the target of the attack, not the initiator, and fails to leverage the FSSO authentication mapping required for user attribution.

88
Multi-Selecthard

During a BGP troubleshooting session, an administrator sees that the BGP neighbor state is 'Active'. Which three conditions could cause this state? (Choose THREE.)

Select 3 answers
A.The remote AS number is misconfigured
B.The BGP update timer is too short
C.The neighbor IP address is incorrectly configured
D.The maximum-prefix limit has been exceeded
E.A firewall is blocking TCP port 179
AnswersA, C, E

ASN mismatch causes the remote end to reject the open message, leading to Active state.

Why this answer

A misconfigured remote AS number causes the BGP neighbor to remain in the 'Active' state. BGP uses the remote AS number to validate the OPEN message; if the AS number in the OPEN message does not match the configured remote AS, the session is rejected, and the neighbor stays in Active, repeatedly attempting to establish a TCP connection.

Exam trap

The trap here is that candidates often confuse 'Active' with 'Idle' or 'Connect' states, mistakenly thinking that a firewall block or misconfiguration would cause 'Idle' instead of 'Active', but 'Active' specifically indicates the router is retrying TCP connection attempts after a failure.

89
MCQeasy

A FortiGate administrator wants to verify whether a specific session is being offloaded to the NP6 processor. Which CLI command should the administrator use?

A.diagnose sys session filter src 10.0.0.1 ; diagnose sys session list
B.get system performance status
C.diagnose hardware sysinfo memory
D.diagnose npu np6 session list
AnswerA

This shows session details and offload status.

Why this answer

The 'diagnose sys session filter src 10.0.0.1' command sets a filter to isolate sessions from a specific source IP, and 'diagnose sys session list' then displays the session details, including the 'offload' field. This field explicitly indicates whether the session is offloaded to the NP6 processor (e.g., 'offload yes' or 'np6 offload'). This is the standard method to verify NP6 offloading for a specific session.

Exam trap

The trap here is that candidates may confuse the generic 'diagnose sys session list' command with the NP6-specific 'diagnose npu np6 session-list' command, but the latter lacks filtering capabilities and is not the correct way to verify offload for a specific session; the exam tests the ability to combine session filtering with the session list output to check the offload flag.

How to eliminate wrong answers

Option B is wrong because 'get system performance status' provides a high-level overview of system resource usage (CPU, memory, sessions) but does not show per-session offload status or NP6-specific details. Option C is wrong because 'diagnose hardware sysinfo memory' reports memory hardware information and usage statistics, not session offloading to NP6 processors. Option D is wrong because 'diagnose npu np6 session list' is not a valid FortiGate CLI command; the correct command to list NP6 offloaded sessions is 'diagnose npu np6 session-list' (with a hyphen), and even then it lists all offloaded sessions without filtering, making it impractical for verifying a specific session without additional filters.

90
MCQmedium

A FortiGate is receiving BGP routes from a neighbor but not advertising them to other peers. The administrator runs 'get router info bgp network' and sees the routes are in the BGP table but not advertised. What is the most likely cause?

A.BGP synchronization is enabled and the routes are not in the IGP
B.An outbound route map is applied that filters these routes
C.The next hop is unreachable
D.The router-id is the same as the peer
AnswerB

An outbound route map attached to the neighbour filters prefixes after they enter the BGP table, so 'get router info bgp network' still lists them while no UPDATE is sent. This directly satisfies the stem's constraint: routes present locally but withheld from peers, which inbound filtering or next-hop issues would not produce.

Why this answer

An outbound route map can explicitly filter which routes are advertised to BGP peers. Even though routes are present in the BGP table (as shown by 'get router info bgp network'), an outbound route map applied to the neighbor configuration can deny or modify those routes before they are sent, preventing their advertisement.

Exam trap

The trap here is that candidates often assume BGP synchronization (Option A) is the cause, but synchronization only affects IBGP-learned routes and is disabled by default in modern implementations, whereas an outbound route map is the direct mechanism controlling advertisement to peers.

How to eliminate wrong answers

Option A is wrong because BGP synchronization (RFC 1771, deprecated in RFC 4271) is disabled by default on FortiGate and, even if enabled, would only affect routes learned from an IBGP peer—not routes being advertised to other peers; the issue here is about outbound advertisement, not IGP reachability. Option C is wrong because if the next hop were unreachable, the routes would not appear in the BGP table as valid; they would be marked as invalid or not installed, but the question states the routes are in the BGP table, implying the next hop is reachable. Option D is wrong because having the same router-id as a peer would cause BGP session establishment to fail (due to duplicate router-id detection), preventing any routes from being received or advertised at all, which contradicts the scenario where routes are already in the BGP table.

91
MCQeasy

An administrator is troubleshooting a FortiGate that is experiencing high CPU usage. The administrator wants to identify which processes are consuming the most CPU. Which command should be used?

A.get system performance status
B.diagnose hardware sysinfo cpu
C.diagnose sys top
D.diagnose sys process list
AnswerC

This command displays a real-time list of running processes along with their CPU and memory usage. It is the primary tool to identify which processes are consuming the most CPU on a FortiGate. The administrator can sort by CPU usage and take appropriate action.

Why this answer

The correct command is 'diagnose sys top' because it provides a real-time, per-process view of CPU and memory usage. This allows the administrator to quickly identify which process is causing high CPU and take corrective action.

Exam trap

The trap here is using a command that only shows overall CPU usage without per-process details, which is insufficient to identify the specific process causing high CPU.

92
MCQeasy

You receive an alert that FortiAnalyzer log disk usage is at 95%. Which action should you take to immediately free up space without losing important logs?

A.Delete all logs older than 30 days
B.Enable log compression
C.Configure log archiving to an external storage
D.Increase log disk quota
AnswerC

Archiving moves older logs to external storage and removes them from the FortiAnalyzer disk, immediately reclaiming space while retaining the data for later retrieval. This satisfies the constraint of freeing space without losing important logs, unlike deletion or reducing retention.

Why this answer

Configuring log archiving to an external storage immediately offloads logs from the FortiAnalyzer local disk to a remote location (e.g., NFS, FTP, or SCP), freeing up disk space without deleting any logs. This preserves all historical log data for compliance and forensic analysis while resolving the high disk usage alert.

Exam trap

The trap here is that candidates often choose to delete logs or increase the quota, mistakenly thinking these are safe or immediate fixes, but the exam tests the understanding that archiving preserves data while freeing space, and that compression or quota changes do not provide instant relief.

How to eliminate wrong answers

Option A is wrong because deleting all logs older than 30 days permanently removes historical data, which may violate compliance requirements and loses important logs that could be needed for incident response or auditing. Option B is wrong because enabling log compression reduces the size of logs on disk but does not immediately free up space—it only affects newly stored logs and requires existing logs to be recompressed, which is not an instant fix. Option D is wrong because increasing the log disk quota does not free up existing space; it merely raises the threshold for disk usage, allowing more logs to be stored until the disk eventually fills again, which does not resolve the immediate 95% usage issue.

93
MCQeasy

An administrator wants to verify that a BGP route is being advertised to a neighbor. Which command displays the routes that FortiGate is advertising to a specific BGP neighbor?

A.get router info bgp network
B.get router info bgp neighbor <ip> advertised-routes
C.diagnose ip router bgp routes
D.show ip bgp summary
AnswerB

The advertised-routes keyword scopes the query to outbound advertisements for that specific peer, satisfying the requirement to verify what FortiGate sends to one neighbour. Without it, the command shows routes received instead, which would not confirm the advertisement.

Why this answer

The command 'get router info bgp neighbor <ip> advertised-routes' is the specific FortiOS CLI command that displays the BGP routes that the FortiGate has advertised to a particular BGP neighbor. This command queries the BGP table for routes that have been sent to the neighbor and are in the Adj-RIB-Out, which is exactly what the administrator needs to verify outbound route advertisement.

Exam trap

The trap here is that candidates often confuse the FortiOS 'get router info bgp neighbor <ip> advertised-routes' command with Cisco's 'show ip bgp neighbors <ip> advertised-routes' or mistakenly use a generic 'show ip bgp summary' command, which only shows neighbor state and not the actual advertised routes.

How to eliminate wrong answers

Option A is wrong because 'get router info bgp network' is not a valid FortiOS command; the correct command to view BGP network statements is 'get router info bgp network' but it shows locally originated networks configured under BGP, not routes advertised to a specific neighbor. Option C is wrong because 'diagnose ip router bgp routes' is not a valid FortiOS command; the 'diagnose' commands are used for debugging and diagnostics, not for displaying BGP advertised routes. Option D is wrong because 'show ip bgp summary' is a Cisco IOS command, not a FortiOS command; the FortiOS equivalent is 'get router info bgp summary', which shows BGP neighbor states and statistics but not advertised routes.

94
MCQmedium

A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The administrator notices that the VPN tunnel is up, but traffic is not passing through it. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is up with the correct selectors. Which command should the administrator use next to verify whether traffic is being encrypted and sent out?

A.diagnose firewall iprope list 100004
B.diagnose ip router lookup <remote_subnet>
C.diagnose sniffer packet any 'host <remote_peer_ip> and esp' 4
D.diagnose vpn ike log filter name <tunnel_name>
AnswerC

This command captures ESP packets between the local and remote peer, showing whether traffic is being encrypted and sent. If no ESP packets are seen, the issue may be with routing, firewall policies, or encryption. This directly verifies if traffic is being encrypted and transmitted.

Why this answer

When an IPsec tunnel is up but traffic is not passing, it is essential to verify whether packets are being encrypted and sent. The sniffer command with an ESP filter captures encrypted packets, confirming if encryption is occurring. If no ESP packets are seen, the issue may be with routing, firewall policies, or encryption domains.

Exam trap

The trap here is assuming that because the tunnel is up, traffic must be encrypted, but it could be dropped by policy or routing before encryption.

95
Multi-Selecthard

A FortiGate is configured with a site-to-site IPsec VPN to a remote office. Users at the remote office report that they cannot access resources at the main office. The administrator checks the VPN status and sees that the tunnel is up. Which two actions should the administrator take to troubleshoot the issue? (Choose two.)

Select 2 answers
A.Run 'diagnose debug application ike -1' to check for IKE errors.
B.Run 'diagnose vpn tunnel list' to view the tunnel status.
C.Restart the IPsec VPN tunnel by clearing the IKE gateway.
D.Run 'diagnose debug flow' with filters for the source and destination IPs.
E.Check the IPsec phase2 selectors to ensure they match the interesting traffic.
AnswersD, E

The debug flow command traces packet processing and can show if traffic is being dropped by a policy, routing issue, or other problem. Since the tunnel is up, the issue is likely with data traffic not being encrypted or decrypted correctly. Using debug flow with appropriate filters will help identify where the packets are being dropped.

Why this answer

Since the IPsec tunnel is up, the issue is likely with data traffic not being properly routed or encrypted. Using diagnose debug flow with filters will trace the packet path and reveal where packets are dropped. Checking phase2 selectors ensures that the traffic matches the encryption domain; mismatched selectors are a common cause of connectivity failures even when the tunnel is established.

Exam trap

The trap here is assuming that a tunnel being up means all traffic will pass, but phase2 selector mismatches or policy issues can still block traffic.

96
Multi-Selecthard

An administrator is troubleshooting a FortiGate that is experiencing high CPU usage. The administrator runs 'diagnose sys top' and sees that the 'ipsengine' process is consuming a large amount of CPU. Which two actions should the administrator take to further diagnose and potentially resolve the issue? (Choose two.)

Select 2 answers
A.Run 'diagnose debug application ipsmonitor -1' to check for IPS engine restarts or errors.
B.Disable IPS inspection on all firewall policies to immediately reduce CPU usage.
C.Increase the FortiGate's memory allocation to the IPS engine via CLI.
D.Check the IPS sensor configuration for overly broad or resource-intensive signatures.
E.Restart the IPS engine using 'diagnose test application ipsmonitor 99' to clear the high CPU.
AnswersA, D

This command enables debugging for the IPS monitor daemon, which manages the IPS engine processes. It can reveal if the IPS engine is repeatedly restarting due to crashes or configuration issues, which would cause high CPU. The output may show messages about engine failures or memory problems, helping to identify the root cause.

Why this answer

To diagnose high CPU from the IPS engine, checking the ipsmonitor debug can reveal if the engine is crashing or restarting, which would cause repeated high CPU spikes. Additionally, reviewing the IPS sensor configuration for heavy signatures or excessive signatures can identify if the load is due to inspection complexity. Both actions target the root cause without compromising security.

Exam trap

The trap here is thinking that restarting the IPS engine or disabling IPS will solve the problem, when the real issue is often misconfiguration or signature overload that requires investigation.

97
MCQmedium

A FortiGate administrator uses FortiAnalyzer for log analysis and wants to identify all sessions that were blocked by a specific firewall policy ID 10. Which log filter should be applied?

A.Filter by 'action eq block' and then manually look for policy 10
B.Filter by 'policyid == 10'
C.Filter by 'policyid eq 10'
D.Filter by 'devid contains 10'
AnswerC

Correct. Using 'policy_id = 10' directly filters for all sessions handled by policy ID 10, including those blocked, using the accepted '=' operator.

Why this answer

The correct filter to identify sessions from a specific policy in FortiAnalyzer is 'policyid eq 10'. This uses the proper field name 'policyid' and the 'eq' operator. Option B uses '==' which is invalid, and option C uses the incorrect field name 'policy_id'.

98
MCQmedium

You run 'diagnose sys session filter dport 443' and see sessions with a duration of 7200 seconds and expire time of 3600 seconds. What does this indicate?

A.The session has been idle for 7200 seconds
B.The session helper is interfering with the session
C.The session has been alive for 7200 seconds and will expire in 3600 seconds
D.The session has already expired
AnswerC

Session duration counts elapsed time since establishment, while expire time counts remaining seconds before teardown. A duration of 7200 with expire time of 3600 therefore means the session has existed for two hours and will close in one more.

Why this answer

The 'duration' field in the 'diagnose sys session filter' output shows how long the session has been active (7200 seconds), while the 'expire' field indicates the remaining time before the session times out (3600 seconds). Option C correctly interprets both values. This is standard FortiGate session table behavior, where each session has a configurable timeout (e.g., default TCP timeout is 3600 seconds for established sessions).

Exam trap

The trap here is confusing 'duration' with 'idle time' — candidates often assume duration measures inactivity, but FortiGate's session table uses separate fields for idle time and total session age.

How to eliminate wrong answers

Option A is wrong because 'duration' measures total session lifetime, not idle time; idle time is tracked separately via the 'idle' field in the session output. Option B is wrong because session helpers (e.g., ALG for SIP or FTP) do not cause a discrepancy between duration and expire time; they modify session behavior but are not indicated by these two fields alone. Option D is wrong because an expired session would not appear in the session list; the expire time of 3600 seconds means the session is still active and will expire in one hour.

99
MCQhard

An administrator is troubleshooting a FortiGate that is dropping traffic from a specific VLAN. The administrator runs 'diagnose debug flow' with a filter for the VLAN's subnet and sees the trace terminate with the message 'iprope_in_check() check failed, drop'. What is the MOST likely cause?

A.The FortiGate is dropping the traffic because the destination route is missing from the routing table.
B.The traffic is being dropped because the VLAN interface is administratively down.
C.The traffic is being dropped by the NP7 processor because the session is not offloaded.
D.The traffic is being denied by a firewall policy or by the implicit deny, because no matching policy was found during the ingress policy check.
AnswerD

The 'iprope_in_check() check failed, drop' message appears when the ingress policy lookup finds no matching policy to permit the traffic, so it falls through to the implicit deny. This is a policy-ordering or policy-matching problem, often caused by a wrong address object, service, or missing policy for that VLAN subnet. The administrator should verify policy order and object definitions.

Why this answer

The iprope_in_check failure in the flow trace indicates the ingress policy lookup found no matching policy, so the packet hit the implicit deny. The administrator should inspect policy order, address objects, and service definitions for the VLAN subnet. Routing, NP7 offload, and interface state produce different symptoms and would not yield this specific message.

Exam trap

The trap here is reading any flow-trace drop as a routing problem, when iprope_in_check specifically points to a firewall policy match failure.

100
MCQmedium

A FortiGate is configured with SD-WAN and multiple members. The administrator notices that traffic to a critical application is consistently routed over a low-quality link, even though a better link is available. The SD-WAN rule uses the 'Best Quality' strategy with a performance SLA. What is the most likely reason?

A.The better link is failing its SLA probes
B.The better link is in 'standby' mode
C.The SD-WAN rule is using source-based routing
D.The application traffic is not matching the SD-WAN rule
AnswerA

Under Best Quality, SD-WAN selects members by measured SLA performance. If the superior link fails its performance SLA probes, it is marked out of SLA and excluded, so traffic falls back to the remaining member despite that link's better raw capacity.

Why this answer

When an SD-WAN rule uses the 'Best Quality' strategy with a performance SLA, the FortiGate selects the member link that best meets the SLA targets (e.g., jitter, latency, packet loss). If the better link is failing its SLA probes, it is considered out of compliance and will not be selected, even if it is physically available and has higher bandwidth. This causes traffic to be routed over the lower-quality link that still passes the SLA.

Exam trap

The trap here is that candidates assume 'Best Quality' always picks the link with the highest bandwidth or lowest cost, when in fact it strictly selects based on SLA compliance, not raw capacity or administrative preference.

How to eliminate wrong answers

Option B is wrong because a link in 'standby' mode is only used for failover when all active links fail; it would not be considered a 'better link' that is available for selection under normal SD-WAN rules. Option C is wrong because source-based routing is a different strategy that ignores SLA performance; the question explicitly states the rule uses 'Best Quality' with a performance SLA, so source-based routing is not in effect. Option D is wrong because if the application traffic were not matching the SD-WAN rule, it would be handled by the regular routing table or policy-based routing, not consistently routed over a low-quality link via the SD-WAN rule.

101
MCQhard

An administrator is troubleshooting a FortiGate that is experiencing intermittent packet loss for traffic passing through an IPsec VPN tunnel. The administrator wants to capture packets on the VPN interface to analyze the issue. Which command should the administrator use to capture packets on the IPsec tunnel interface named 'vpn1'?

A.diagnose debug application ike -1
B.diagnose sniffer packet port1 'host 10.1.1.1' 4
C.diagnose sniffer packet vpn1 'host 10.1.1.1' 4
D.diagnose sniffer packet any 'host 10.1.1.1' 4
AnswerC

This command captures packets on the 'vpn1' interface with a filter for host 10.1.1.1 and verbosity level 4, which provides detailed packet information including interface names. This is the correct syntax to capture traffic on a specific IPsec tunnel interface for troubleshooting packet loss.

Why this answer

To capture packets on a specific IPsec tunnel interface, the administrator should use 'diagnose sniffer packet <interface>' with the appropriate filter and verbosity. This allows capturing the decrypted traffic inside the tunnel, which is essential for analyzing packet loss. Capturing on the physical interface would only show encrypted packets.

Exam trap

The trap here is capturing on the physical interface or 'any' and assuming it will show the tunneled traffic, when in fact the VPN interface must be specified to see the decrypted packets.

102
MCQmedium

A network admin runs 'diagnose sys top' on a FortiGate and sees that the process 'httpsd' is consistently using 95% CPU. Which of the following actions is MOST appropriate to troubleshoot this issue?

A.Restart the FortiGate firewall engine with 'diagnose test application fgwbd 255'
B.Disable the antivirus profile on all policies to reduce processing load
C.Increase the log rate to capture more details about the httpsd process
D.Check the number of active admin sessions and consider stopping the web GUI service temporarily
AnswerD

httpsd handles web management; high CPU may be due to many admin sessions or a stuck process.

Why this answer

The httpsd process handles the FortiGate web GUI (HTTPS) and API requests. High CPU usage by httpsd typically indicates excessive admin sessions or web GUI activity. Option D is correct because checking active admin sessions and temporarily stopping the web GUI service (e.g., via 'config system global set admin-https-redirect disable' or stopping the service) directly addresses the likely cause without disrupting firewall processing or requiring policy changes.

Exam trap

The trap here is that candidates may confuse the httpsd process with the firewall engine (fgwbd) and attempt to restart the firewall engine, or assume high CPU is always due to security profiles, when in fact httpsd is a management-plane process that requires a different troubleshooting approach.

How to eliminate wrong answers

Option A is wrong because 'diagnose test application fgwbd 255' restarts the firewall engine (fgwbd), which handles firewall processing, not the httpsd process; this would disrupt traffic without addressing the root cause. Option B is wrong because disabling antivirus profiles on all policies reduces security and does not affect the httpsd process, which is a web server process unrelated to AV scanning. Option C is wrong because increasing the log rate adds overhead to the system and does not provide diagnostic details specific to httpsd; logs for httpsd are already captured in the event log and increasing rate would worsen CPU usage.

103
MCQeasy

An administrator wants to monitor real-time CPU usage per process on a FortiGate. Which command should be used?

A.diagnose hardware sysinfo cpu
B.get system performance status
C.diagnose sys top
D.show system performance monitor
AnswerC

The diagnose sys top command displays a live, refreshing list of running processes with their CPU and memory consumption, letting the administrator identify which process is consuming resources in real time. It is the FortiGate diagnostic equivalent of a Unix top utility.

Why this answer

The 'diagnose sys top' command on FortiGate displays real-time CPU usage per process, similar to the Linux 'top' command. This is the standard diagnostic tool for monitoring per-process CPU and memory consumption in real time, which directly meets the administrator's requirement.

Exam trap

The trap here is that candidates may confuse 'diagnose sys top' with 'get system performance status' or 'diagnose hardware sysinfo cpu', which provide aggregate CPU data but not per-process granularity, leading to an incorrect choice when the question explicitly asks for per-process monitoring.

How to eliminate wrong answers

Option A is wrong because 'diagnose hardware sysinfo cpu' shows overall CPU utilization and hardware information, not per-process breakdown. Option B is wrong because 'get system performance status' provides a summary of system performance metrics (e.g., CPU, memory, sessions) but does not list individual processes. Option D is wrong because 'show system performance monitor' is not a valid FortiGate CLI command; the correct command for a performance monitor view is 'diagnose sys perf' or 'diagnose sys top'.

104
Multi-Selectmedium

An administrator is configuring SD-WAN and wants to ensure that voice traffic uses the lowest latency link. Which two configurations are required to achieve this? (Choose TWO.)

Select 2 answers
A.Configure a static route for the voice subnet
B.Configure a performance SLA with latency threshold
C.Set the SD-WAN rule to use 'manual' strategy
D.Create an SD-WAN rule that matches voice traffic and uses 'best quality' strategy
E.Enable NAT on the SD-WAN interface
AnswersB, D

A performance SLA with a latency threshold continuously probes each member link, measuring jitter and packet loss against the configured latency limit. SD-WAN then steers voice traffic onto the link satisfying that threshold, directly meeting the requirement for lowest-latency path selection.

Why this answer

A performance SLA with a latency threshold allows FortiGate to measure real-time latency to a target server and mark the link quality. Option D is correct because an SD-WAN rule using the 'best quality' strategy will dynamically select the link with the lowest latency (as determined by the SLA) for voice traffic, ensuring optimal voice quality.

Exam trap

The trap here is that candidates often confuse 'manual' strategy with 'best quality', assuming manual allows manual selection of the best link, but manual actually forces a fixed interface without dynamic SLA feedback.

105
MCQhard

A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The administrator notices that the VPN tunnel is up, but traffic is not passing through it. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established with the correct selectors. The administrator then runs 'diagnose debug flow filter addr 10.1.1.1' (the remote subnet) and 'diagnose debug flow show function-name enable', and observes the following output: 'id=20085 trace_id=1 func=print_pkt_detail line=4793 msg="vd-root:0 received a packet(proto=6, 10.1.1.1:80->192.168.1.100:12345) from port1. flag [S], seq 123456, ack 0, win 8192"' followed by 'id=20085 trace_id=1 func=init_ip_session_common line=4970 msg="allocate a new session-00000123"' and then 'id=20085 trace_id=1 func=vf_ip_route_input_common line=2580 msg="find a route: flag=04000000 gw-192.168.1.1 via port2"'. No further output appears. What is the MOST likely cause of the issue?

A.The FortiGate is routing the traffic to the default gateway instead of into the IPsec tunnel, likely due to a missing or incorrect route for the remote subnet.
B.The IPsec VPN tunnel is not included in the firewall policy that allows traffic from the local subnet to the remote subnet.
C.The IPsec tunnel is using a different encryption domain than the local subnet, causing the FortiGate to drop the traffic.
D.The remote subnet is not correctly configured in the phase 2 selectors, causing traffic to be routed incorrectly.
AnswerA

The debug flow output shows that the FortiGate performed a route lookup and found a route to 192.168.1.1 via port2, which is the default gateway, not the IPsec tunnel. This indicates that there is no specific route for the remote subnet 10.1.1.0/24 pointing to the IPsec interface. Without that route, the FortiGate sends the traffic out the default gateway, where it is likely dropped or not encrypted. The administrator should add a static route for the remote subnet with the IPsec interface as the outgoing interface.

Why this answer

The debug flow output shows that the FortiGate received the packet, allocated a session, and then performed a route lookup that resulted in a route via the default gateway (192.168.1.1) on port2. This means the FortiGate is not sending the traffic into the IPsec tunnel, which would be indicated by a route via the IPsec interface. The most likely cause is that there is no static route for the remote subnet pointing to the IPsec tunnel.

Without that route, traffic is routed to the default gateway and not encrypted. The administrator should verify the routing table and add the necessary route.

Exam trap

The trap here is assuming the VPN tunnel configuration is at fault, but the debug flow clearly shows the traffic is being routed out the default gateway instead of the tunnel.

106
MCQhard

A FortiGate cluster (A-P) has a session that is not synchronizing to the secondary unit. The administrator runs 'diagnose sys ha session-sync status' and sees that the session count is different between primary and secondary. Which is the most likely cause?

A.The session is using a custom application control profile that prevents synchronization.
B.The HA heartbeat interface is down.
C.The secondary unit has insufficient memory to accept new sessions.
D.The session was created by a local-in traffic (e.g., management traffic) which is not synchronized.
AnswerD

Local-in traffic terminates on the FortiGate itself, so those sessions are never replicated to the secondary unit. This explains the count mismatch without indicating an HA failure, since session synchronisation only covers transit traffic passing through the cluster.

Why this answer

FortiGate A-P clusters synchronize sessions via the HA heartbeat interface, but local-in traffic (e.g., management sessions like HTTPS, SSH, or SNMP) is never synchronized because it is destined to the cluster IP itself and is inherently unit-specific. The 'diagnose sys ha session-sync status' command shows a session count mismatch because the primary unit has local-in sessions that the secondary does not replicate, making D the correct answer.

Exam trap

The trap here is that candidates assume all sessions are synchronized by default, but FortiGate explicitly excludes local-in traffic (management sessions) from HA synchronization, so a session count difference is normal and expected for those sessions.

How to eliminate wrong answers

Option A is wrong because application control profiles do not affect session synchronization; they are inspection profiles applied to traffic policies, and session synchronization is controlled by HA settings and session type, not by security profiles. Option B is wrong because if the HA heartbeat interface were down, the cluster would not be able to maintain a synchronized state at all, and the secondary would likely be isolated or the cluster would split-brain; the question states the cluster is operational with a session count difference, not a total sync failure. Option C is wrong because insufficient memory on the secondary would cause it to reject new sessions or fail to synchronize, but the symptom would be a growing session count mismatch over time, not a persistent difference for a specific session; moreover, the secondary would still attempt synchronization and log memory pressure, not simply skip a session silently.

107
MCQeasy

A FortiGate administrator wants to quickly identify which process is consuming the most CPU on the device. Which CLI command should be used?

A.diagnose hardware sysinfo memory
B.diagnose sys top
C.diagnose debug application crashlog read
D.get system performance status
AnswerB

diagnose sys top lists running processes sorted by CPU consumption, refreshed live, so the administrator immediately sees which process is heaviest. This directly satisfies the stem's goal of quickly identifying the top CPU consumer on the FortiGate.

Why this answer

'diagnose sys top' displays a real-time list of running processes sorted by CPU usage, allowing the administrator to quickly identify the most CPU-intensive process. This command is the standard FortiGate CLI tool for live process-level CPU monitoring, similar to the Linux 'top' command.

Exam trap

The trap here is that candidates often confuse 'get system performance status' (which shows aggregate CPU percentage) with the process-level detail needed, leading them to choose option D instead of the correct process-specific command.

How to eliminate wrong answers

Option A is wrong because 'diagnose hardware sysinfo memory' shows memory usage statistics, not CPU consumption by process. Option C is wrong because 'diagnose debug application crashlog read' is used to view crash logs for debugging application failures, not for real-time CPU monitoring. Option D is wrong because 'get system performance status' provides a high-level summary of system resource usage (CPU, memory, sessions) but does not break down CPU usage by individual process.

108
Multi-Selectmedium

An administrator is configuring a FortiGate to inspect SMTP traffic for spam and viruses. The traffic must be decrypted to inspect the content. Which THREE elements are required for this configuration? (Choose three.)

Select 3 answers
A.A spam filter profile applied to the firewall policy
B.A web filter profile applied to the firewall policy
C.An antivirus profile applied to the firewall policy
D.An application control profile applied to the firewall policy
E.A firewall policy that allows SMTP traffic and has SSL inspection enabled
AnswersA, C, E

Spam filtering is needed to identify and block spam.

Why this answer

A spam filter profile is required to inspect SMTP traffic for spam. FortiGate uses this profile to apply anti-spam techniques such as DNSBL, SURBL, and heuristic analysis on the email content after decryption. Without it, spam detection cannot occur.

Exam trap

The trap here is that candidates often assume a web filter profile can inspect email traffic because it handles content filtering, but web filters are strictly for HTTP/HTTPS protocols and cannot process SMTP MIME data.

109
MCQhard

An administrator runs 'diagnose debug application sslvpn -1' and sees repeated 'SSL_ERROR_SSL: error:1417C0C7:SSL routines:tls_process_client_certificate:peer did not return a certificate'. The SSL-VPN is configured to require client certificates. What is the cause?

A.The client is not sending a client certificate
B.The SSL-VPN server certificate is expired
C.The SSL-VPN tunnel mode is misconfigured
D.The CA certificate is not imported on FortiGate
AnswerA

The TLS alert fires during the client certificate request phase, meaning the peer returned no certificate at all. Since the SSL-VPN profile enforces client certificate authentication, the handshake cannot proceed without one, so the connecting client simply has no certificate installed or configured to present.

Why this answer

The error 'SSL_ERROR_SSL: error:1417C0C7:SSL routines:tls_process_client_certificate:peer did not return a certificate' occurs during the TLS handshake when the server requests a client certificate and the client fails to provide one. Since the SSL-VPN is configured to require client certificates, the FortiGate expects the client to present a valid certificate; if none is sent, the handshake fails with this specific OpenSSL error. This directly indicates that the client is not sending a client certificate, making option A correct.

Exam trap

The trap here is that candidates may confuse a client certificate not being sent with a CA certificate not being imported on the FortiGate, but the error message explicitly points to the absence of a certificate from the client, not a validation failure after receipt.

How to eliminate wrong answers

Option B is wrong because an expired SSL-VPN server certificate would produce a different error, such as 'certificate expired' or 'certificate verify failed', not a 'peer did not return a certificate' message. Option C is wrong because tunnel mode misconfiguration (e.g., using tunnel mode instead of web mode) affects how traffic is encapsulated, not the TLS client certificate exchange; the error is specific to the SSL handshake layer. Option D is wrong because the CA certificate not being imported on the FortiGate would prevent validation of the client certificate if one were sent, but the error clearly states the peer did not return a certificate at all, indicating the client failed to send one, not that validation failed.

110
MCQeasy

Which two commands display the current session count on a FortiGate?

A.get system performance status
B.diagnose sys session stat
C.show system session
D.diagnose hardware sysinfo session
AnswerA, B

The get system performance status command reports overall health counters, including the current session count alongside CPU, memory and uptime figures. It satisfies the stem by displaying the live session total directly from the FortiGate CLI without diagnostic-level inspection.

Why this answer

Both 'get system performance status' and 'diagnose sys session stat' display the current session count on a FortiGate. 'get system performance status' provides a real-time snapshot including active sessions, while 'diagnose sys session stat' shows session table statistics such as total and used sessions. Therefore, both commands are valid answers to the question.

Exam trap

Candidates often think only 'get system performance status' shows session count, but 'diagnose sys session stat' also provides session statistics including count. The trap is that both commands are valid, making this a multi-select question.

How to eliminate wrong answers

Option B is wrong because 'diagnose sys session stat' displays detailed statistics about session table usage (e.g., total sessions, hash table collisions) but does not directly show the current active session count in a single line; it requires parsing of output. Option C is wrong because 'show system session' is not a valid FortiGate CLI command; the correct syntax for viewing session details is 'diagnose sys session list' or 'get system session' (though the latter is not standard). Option D is wrong because 'diagnose hardware sysinfo session' is not a valid command; the correct command for hardware-related session info is 'diagnose hardware sysinfo' (which shows CPU/memory info) but does not include session count.

111
MCQhard

An administrator is troubleshooting an issue where a FortiGate is not forwarding traffic between two internal subnets. The administrator runs 'diagnose debug flow' and sees that packets are entering the FortiGate but are dropped with the message 'reverse path check fail, drop'. What is the MOST likely cause?

A.The FortiGate's routing table does not have a route to the destination subnet.
B.Asymmetric routing: the return path for the traffic is through a different interface than the FortiGate expects.
C.A firewall policy is missing to allow traffic between the two subnets.
D.The two subnets are in the same zone, and intra-zone traffic is denied by default.
AnswerB

The reverse path check verifies that the return packet would be routed back through the same interface it arrived on. If the return route points to a different interface, the check fails and the packet is dropped. This is common in networks with multiple paths, such as when a router between subnets sends traffic through one FortiGate but the return path goes through another.

Why this answer

The 'reverse path check fail' drop indicates that the FortiGate received a packet on an interface but the route back to the source would use a different interface. This is characteristic of asymmetric routing. The FortiGate performs a reverse path forwarding check to prevent spoofing and ensure symmetric routing.

To resolve, the administrator can either fix the routing to be symmetric or disable the reverse path check on the interface, though that reduces security.

Exam trap

The trap here is confusing reverse path check failures with policy or routing table misses, when the message specifically points to asymmetric routing.

112
MCQmedium

When troubleshooting an IPsec VPN phase 1 failure, you run 'diagnose vpn ike config' and see that the remote gateway IP address is incorrect. Which command is used to correct the peer IP configuration?

A.set psksecret <secret>
B.execute vpn tunnel down <tunnel>
C.config vpn ipsec phase1-interface edit <name> set remote-gw <ip>
D.set certificate <name>
AnswerC

Editing the phase1-interface object and setting remote-gw directly corrects the peer address that phase 1 negotiation uses, satisfying the stem's requirement to fix the incorrect remote gateway IP. The `diagnose vpn ike config` output reflects this value, so amending it here resolves the mismatch causing the failure.

Why this answer

The 'config vpn ipsec phase1-interface' command allows you to edit the phase1 configuration, and the 'set remote-gw <ip>' command directly corrects the peer IP address. This is the standard FortiGate CLI method to update the remote gateway IP for an IPsec VPN phase1 interface, which is essential for establishing the IKE session.

Exam trap

The trap here is that candidates may confuse operational commands (like 'execute vpn tunnel down') with configuration commands, or mistake authentication settings (PSK or certificate) for peer addressing, leading them to select options that do not actually change the remote gateway IP.

How to eliminate wrong answers

Option A is wrong because 'set psksecret <secret>' configures the pre-shared key, not the remote gateway IP address; it addresses authentication, not peer reachability. Option B is wrong because 'execute vpn tunnel down <tunnel>' only tears down an existing tunnel, but does not modify the configuration; it is a troubleshooting command, not a correction command. Option D is wrong because 'set certificate <name>' assigns a certificate for authentication, which is unrelated to correcting the peer IP address.

← PreviousPage 2 of 2 · 112 questions total

Ready to test yourself?

Try a timed practice session using only Nse7 Troubleshooting questions.