nerdexam
Fortinet

NSE4 · Question #354

An administrator is using the FortiGate built-in sniffer to capture HTTP traffic between a client and a server, however, the sniffer output shows only the packets related with TCP session setups and d

Sign in or unlock NSE4 to reveal the answer and full explanation for question #354. The question stem and answer options stay visible for context.

Submitted by thandi_sa· Apr 18, 2026Logging and Monitoring

Question

An administrator is using the FortiGate built-in sniffer to capture HTTP traffic between a client and a server, however, the sniffer output shows only the packets related with TCP session setups and disconnections. Why?

Options

  • AThe administrator is running the sniffer on the internal interface only.
  • BThe filter used in the sniffer matches the traffic only in one direction.
  • CThe FortiGate is doing content inspection.
  • DTCP traffic is being offloaded to an NP6.

Unlock NSE4 to see the answer

You've previewed enough free NSE4 questions. Unlock NSE4 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Packet Sniffer#Troubleshooting#FortiGate Diagnostics#TCP Session Flow
Full NSE4 Practice