Courseiva

NSE4 High Availability and Diagnostics Practice Question

A FortiGate admin runs 'diagnose sys session filter dport 443' and then 'diagnose sys session list'. The output shows a session with 'proto=6 proto_state=01 duration=3600 expire=3599'. What does this indicate about the session?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The session is in a half-open state, waiting for SYN-ACK

Protocol 6 is TCP, proto_state=01 indicates TCP SYN_SENT state (the first step of the three-way handshake). Duration and expire are in seconds. The session has been open for 3600 seconds (1 hour) and will expire in 3599 seconds, which is unusual for a TCP session that should have completed handshake quickly. This suggests the session is stuck in SYN_SENT, likely due to no SYN-ACK response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The session is in a half-open state, waiting for SYN-ACK

    Why this is correct

    The session's proto_state value of 01 corresponds to SYN_SENT, indicating the client's SYN has been sent but no SYN-ACK has yet been received from the server. This creates a half-open session that is stuck waiting for the server to respond, often due to packet loss, a misconfigured server, or an intermediate device silently dropping the SYN-ACK. Until that reply arrives, the session cannot transition to the fully established state.

  • ✗

    The session is closing with a FIN flag

    Why it's wrong here

    A FIN flag initiates the TCP teardown sequence, and FortiGate tracks such sessions with distinct proto_state values like FIN_WAIT (03), CLOSE_WAIT (04), or TIME_WAIT (05), not SYN_SENT (01). A session in SYN_SENT is still in the initial handshake phase and has never progressed to the point where a FIN could be exchanged. Thus, seeing proto_state=01 means the session is incomplete, not actively closing.

  • ✗

    The session is fully established and transferring data

    Why it's wrong here

    An established TCP session that is actively transferring data would have a proto_state value of 02 (ESTABLISHED) in FortiGate's session table. The observed proto_state=01 (SYN_SENT) clearly indicates the handshake is still in progress, so no data payload has been exchanged yet. If the session were fully up, the state would be ESTABLISHED, not SYN_SENT.

  • ✗

    The session was blocked by a firewall policy

    Why it's wrong here

    Firewall policy blocks, or 'deny' actions, cause packets to be dropped at the policy evaluation layer without ever creating a session entry in FortiGate's session table. The fact that a session record exists with proto_state=01 proves that the initial SYN matched an 'accept' policy and a tracking entry was allocated for the handshake. Therefore, a blocked session would never appear in the session table, let alone show a SYN_SENT state.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.