NSE4 System and Network Administration Practice Question
An administrator runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?
⚠ Common exam trap
The trap here is that candidates misinterpret `proto_state=01` as a generic 'active' state without knowing Fortinet's specific numeric encoding, leading them to confuse it with FIN_WAIT or TIME_WAIT states that have different numeric values and shorter expire times.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The session is in established state and has been active for 1 hour
The output shows `proto=6` (TCP), `proto_state=01` (ESTABLISHED state per Fortinet's session state encoding), `duration=3600` seconds (1 hour), and `expire=3599` seconds (nearly full lifetime remaining). This indicates the session is actively established and has been ongoing for one hour, matching the description of an established state session.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The session is in established state and has been active for 1 hour
Why this is correct
The session entry shows proto_state=01, which in Fortinet's session table maps to TCP-established. The duration field of 3600 is expressed in seconds, so the session has been continuously active for exactly one hour. This is the normal state for an ongoing HTTPS connection on port 443, so this option correctly interprets the output.
- ✗
The session is in FIN_WAIT state
Why it's wrong here
A TCP session in FIN_WAIT (state 03 or 04 depending on whether it is FIN_WAIT1 or FIN_WAIT2) indicates that the connection is in the process of closing. The local endpoint has already sent a FIN and is waiting for the peer's FIN or acknowledgment; this is not a fully active data-transfer state. Because the output explicitly shows proto_state=01, the session cannot be in FIN_WAIT.
- ✗
The session is in TIME_WAIT state and will close soon
Why it's wrong here
TIME_WAIT (state 07 in Fortinet's session table) is a cleanup state that occurs after one side has sent a FIN and the connection has been fully closed, not a state that indicates an active session. The comment that it 'will close soon' is misleading because TIME_WAIT persists for a fixed timeout (typically 2*MSL) to handle delayed packets. Since the observed state is 01, this option misreads the state code.
- ✗
The session is in SYN_SENT state waiting for a SYN-ACK
Why it's wrong here
SYN_SENT (state 02) represents an incomplete TCP handshake where a SYN has been transmitted and the initiator is waiting for a SYN-ACK; it is a transient opening state, not an established session. A session in this state would not have a duration of 3600 seconds because handshakes complete in milliseconds under normal conditions. The actual proto_state=01 confirms the handshake finished long ago and the connection is fully established.
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.