Courseiva

NSE4 High Availability and Diagnostics Practice Question

A FortiGate administrator runs 'diagnose sys session filter dport 443' followed by 'diagnose sys session list' and sees the following output for a session: src=10.0.1.10 dst=192.168.2.20 sport=12345 dport=443 proto=6 vrf=0

What does the 'proto=6' indicate about this session?

⚠ Common exam trap

NSE4 often tests whether candidates know IANA protocol numbers in session output, trapping those who confuse proto=6 with UDP or assume the protocol from the port number alone.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The session is using TCP

In IP protocol numbers, 6 represents TCP. The session output shows proto=6, which means the session is using TCP. This is consistent with dport=443, the standard HTTPS port over TCP. The FortiGate session table uses IANA protocol numbers to identify the transport protocol.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The session is using UDP

    Why it's wrong here

    UDP is not the correct answer because it uses IP protocol number 17, not 6. In FortiGate session tables, a UDP flow is identified by the protocol field 'Proto=17' in the output of 'diagnose sys session list' or when applying filters. Common UDP-based services such as DNS or DHCP would therefore show a different protocol number, so the session described would not be UDP. Thus, the session cannot be UDP when protocol number 6 is observed.

  • ✗

    The session is using ESP

    Why it's wrong here

    ESP, which stands for Encapsulating Security Payload, is an IPsec protocol that uses IP protocol number 50, not 6. When an administrator sees an IPsec tunnel or encrypted ESP traffic in a FortiGate session table, the protocol field displays 'Proto=50' as the numeric value. This distinguishes ESP from other transport-layer protocols like TCP or UDP. Since the observed protocol number is specifically 6, the session is not ESP but rather TCP.

  • ✓

    The session is using TCP

    Why this is correct

    TCP, or Transmission Control Protocol, is indeed assigned IP protocol number 6, which is what the session filter output indicates. This is standard across all IP networks, as defined by the IANA protocol numbers. A FortiGate session for applications such as HTTP, SSH, or SMTP would show 'Proto=6' to represent TCP. Therefore, the correct interpretation of the protocol numeral in the diagnostic output is that the session is using TCP as its transport layer protocol.

  • ✗

    The session is using ICMP

    Why it's wrong here

    ICMP is a network-layer protocol used for diagnostics such as ping and tracert, and it is identified by IP protocol number 1, not 6. In FortiGate's session diagnostics, ICMP packets appear with 'Proto=1' in the session list, and they have no source or destination port information because ICMP does not use ports. The presence of protocol number 6 in the filter output rules out ICMP, confirming that the session is not an ICMP-based exchange. Thus, ICMP cannot be the correct answer here.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.