Courseiva
Firewall Policies and NAT →mediumMultiple Choice

NSE4 Firewall Policies and NAT Practice Question

A FortiGate administrator runs the following command and sees output: diagnose sys session filter dport 443 diagnose sys session list ... proto=6 proto_state=01 duration=3600 expire=3599 What does this output indicate about the session?

⚠ Common exam trap

Candidates often confuse `duration` with `expire`, assuming a high duration means the session is about to end, when in fact `expire` shows the remaining lifetime, and `proto_state=01` is the key indicator of an active established TCP session.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The session is an active TCP connection that has been established for 1 hour

The output shows `proto=6`, which is the protocol number for TCP, and `proto_state=01`, which in FortiGate's session table indicates an established TCP connection (state ESTABLISHED). The `duration=3600` seconds means the session has been active for exactly 1 hour, and `expire=3599` seconds shows the remaining time before the session times out. This confirms the session is an active TCP connection that has been established for 1 hour, making option C correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The session has expired

    Why it's wrong here

    The session has not expired. The 'expire=3599' field shows the remaining session lifetime in seconds, meaning roughly 3599 seconds are still left before the session is torn down. A session that has expired would be absent from the table or show expire=0, and the 'duration=3600' field confirms 3600 seconds have already elapsed, so the session is currently alive and actively tracked.

  • ✗

    The session is being blocked by a firewall policy

    Why it's wrong here

    A firewall policy that blocks traffic would prevent a session from being created in the first place; FortiOS does not log a 'blocked' session as an active entry in the session table. The session listed here is in an established state with both directions of traffic seen, indicating the policy has allowed it. If it were being blocked, you would see a deny log or no session entry at all, not a healthy session with a countdown timer.

  • ✓

    The session is an active TCP connection that has been established for 1 hour

    Why this is correct

    This is correct because 'duration=3600' means the connection has been established for exactly 3600 seconds, which is 1 hour, and 'proto=6' is the IP protocol number for TCP. The 'expire=3599' field shows the remaining lifetime in seconds, so the session is still active. An established TCP session with bidirectional traffic is exactly what a FortiGate tracks in its session table, confirming it is not merely a one-way packet but an ongoing connection.

  • ✗

    The session is using UDP

    Why it's wrong here

    The session is not using UDP because the protocol field shows 'proto=6', and protocol number 6 is assigned to TCP, not UDP (which is protocol 17). UDP sessions in FortiOS typically appear with a shorter expiry and do not have a TCP 'established' state; they are connectionless and often show 'proto=17' instead. This session's TCP-specific attributes, such as a long duration and stateful tracking, further rule out UDP.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.