NSE4 Firewall Policies and NAT Practice Question
A FortiGate admin runs 'diagnose sys session filter src 10.0.0.10' and gets no output. What does this indicate?
⚠ Common exam trap
It's easy for candidates to assume no output means a syntax error or a full session table, but FortiGate clearly indicates syntax errors with an error message, and a full table still shows existing sessions; the correct interpretation is that the source IP has no active sessions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The source IP 10.0.0.10 is not currently active in any session table
The 'diagnose sys session filter' command in FortiGate is used to filter and display active session entries in the session table. When the command 'diagnose sys session filter src 10.0.0.10' returns no output, it means that no session in the session table matches the source IP address 10.0.0.10, indicating that this IP is not currently involved in any active session. This does not imply the session table is full, a policy block, or a syntax error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The session table is full
Why it's wrong here
The session table full condition would not produce an empty filter result. If the table is full, it contains many sessions, but the filter is specific to source IP 10.0.0.10, so any existing session from that IP would still be listed. A full table primarily causes new session establishment to fail, but it does not clear or hide existing entries. Therefore, an empty output indicates no session exists from that source IP, not that the table lacks capacity.
- ✓
The source IP 10.0.0.10 is not currently active in any session table
Why this is correct
The kernel session table tracks active, stateful connections, and when you apply a source-IP filter, it displays only sessions whose source address matches the filter. If no output is returned, it means the source 10.0.0.10 currently has no session entry — the host is idle, its session expired or was torn down, or it never established one. This is a straightforward observation of the session table state, not a sign of a performance or configuration issue.
- ✗
The firewall policy is blocking traffic from 10.0.0.10
Why it's wrong here
A firewall policy that blocks traffic from 10.0.0.10 would drop the packets and, by default, not create any session entry, so the filter would also show nothing. However, this command only inspects the session table; it does not indicate the reason why a session is absent. Blocked traffic, failed handshakes, or simply no traffic at all all leave the same empty output. Thus, seeing no sessions does not prove that a policy is blocking the source.
- ✗
The diagnose command syntax is incorrect
Why it's wrong here
The command 'diagnose sys session filter src 10 0' is not malformed; FortiOS recognizes this filter syntax correctly. If the syntax were invalid, the CLI would immediately return an error such as 'unknown argument' or usage help, rather than silently producing no output. Since the command executes and simply displays nothing, it confirms the syntax is valid and the lack of output is a legitimate empty result. Therefore this option is not the cause.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.