Courseiva

NSE7 Resource Utilization Practice Question

Which TWO actions are appropriate when troubleshooting a slow network connection through a FortiGate?

⚠ Common exam trap

Candidates often assume disabling security features (Option E) or adjusting session timers (Option A) are quick fixes, but the NSE7 exam expects systematic troubleshooting starting with resource utilization and routing verification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check the CPU and memory utilization on the FortiGate.

Option B is correct because high CPU or memory utilization on the FortiGate can directly degrade throughput and cause slow connections, so checking resource usage via commands like 'get system performance status' or the dashboard is a standard first troubleshooting step. Option C is correct because an incorrect or missing next-hop entry in the routing table (verifiable with 'get router info routing-table all') can cause suboptimal paths, asymmetric routing, or packet drops that manifest as slow network performance. Option A is not appropriate because increasing session TTL does not reduce session setup overhead and can actually consume more session table resources. Option D is wrong because disabling flow control on the WAN interface can worsen performance by allowing buffer overruns and packet loss rather than fixing slowness. Option E is wrong because disabling all security profiles is a drastic, security-compromising action that is not a legitimate troubleshooting step for slow connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the session TTL to reduce session setup overhead.

    Why it's wrong here

    Increasing session TTL does not address slow throughput; it only keeps idle sessions alive longer, consuming more session table entries. It is tempting because reducing session setup overhead sounds relevant to latency, but this would be correct only when frequent session re-establishment, not slow transfer, is the bottleneck.

  • ✓

    Check the CPU and memory utilization on the FortiGate.

    Why this is correct

    Slow throughput often stems from resource exhaustion, since FortiGate inspection, NP offload and session handling all consume CPU and memory. Checking utilisation identifies whether the appliance itself is the bottleneck before investigating upstream or downstream causes.

  • ✓

    Verify the routing table for correct next-hop entries.

    Why this is correct

    Incorrect or missing next-hop entries cause traffic to take suboptimal paths, be dropped, or loop, all of which present as slow connections. Verifying the routing table confirms packets egress the expected interface toward the correct gateway.

  • ✗

    Disable flow control on the WAN interface.

    Why it's wrong here

    Disabling flow control on the WAN interface can cause packet loss and retransmissions, worsening slowness rather than fixing it. It is tempting because flow control misconfiguration can cause performance issues, so disabling it would be correct only when flow control is actually causing pauses, not as a general troubleshooting step.

  • ✗

    Disable all security profiles to free resources.

    Why it's wrong here

    Disabling all security profiles removes inspection but does not diagnose the cause of slowness, and it exposes the network unnecessarily. It is tempting because security processing can add latency, so this would be correct only when profiling has already identified a specific profile as the bottleneck.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.