# NSE7 — Question 427

**Type:** multiple_choice
**Topics:** topic_1

## Question

Examine the following partial output from a sniffer command; then answer the question below.
//IMG//

What is the meaning of the packets dropped counter at the end of the sniffer?

## Correct Answer

_See scenario._

## Explanation

The Fortinet device may not display all packets if too much information is requested to be displayed, or the traffic being sniffed is significant. When this occurs, the unit will log the following message once the trace is terminated:

12151 packets received by filter

3264 packets dropped by kernel

When this occurs, it is possible that what you were attempting to capture was not actually captured. In order to avoid this, you may try to tighten the display filters, reduce the verbose level, or perform the trace during a lower traffic period.

**Reference:** examtopics_top_comment

---
Source: https://hiexam.net/q/fortinet/NSE7/427  
Practice (tracked): https://hiexam.net/study/NSE7/practice