Courseiva
Security Profiles →hardMultiple Choice

NSE4 Security Profiles Practice Question

An administrator runs the command 'diagnose ips anomaly list' and sees many entries for 'tcp_src_session' with high counts. Users report slow internet. What is the most likely issue?

⚠ Common exam trap

It's easy for candidates to confuse 'tcp_src_session' (outbound from a source) with 'tcp_dst_session' (inbound to a destination) and incorrectly assume a DDoS attack, but the command specifically shows the source IP, not the destination, pointing to an internal infected host rather than an external attack.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A host on the network is infected with malware that is generating many outbound connections

The 'diagnose ips anomaly list' command displays anomalies detected by the IPS engine, and 'tcp_src_session' tracks the number of TCP sessions originating from a single source IP. A high count indicates a single host is initiating an excessive number of outbound TCP connections, which is a classic sign of malware infection (e.g., a botnet client or worm) that is generating numerous outbound connections, consuming bandwidth and causing slow internet for users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IPS signature database is corrupted

    Why it's wrong here

    Anomaly detection in FortiOS does not rely on the IPS signature database; it uses protocol decoders and heuristics to identify abnormal traffic behaviors such as excessive sessions, port scans, or source IP spoofing. A corrupted signature database would typically produce signature load errors or prevent pattern-matching updates, but it would not generate specific anomaly list entries. Therefore, this output indicates a heuristic-based anomaly event, not a database integrity problem.

  • ✗

    The FortiGate has a hardware failure

    Why it's wrong here

    A hardware failure on a FortiGate would manifest as crashes, interface flaps, power supply faults, or CPU/memory hardware watchdog alarms, not as a list of detected network anomalies. The `diagnose ips anomaly list` command reports active IPS anomaly detection events, which are derived from traffic analysis and pattern heuristics, not from the hardware health of the device. Thus, the presence of anomaly entries is unrelated to physical hardware status.

  • ✓

    A host on the network is infected with malware that is generating many outbound connections

    Why this is correct

    A single internal host generating a high volume of outbound connections to multiple external destinations is a hallmark of malware infection or P2P activity. FortiOS IPS anomaly detection monitors such behavioral patterns—like excessive half-open connections or a source creating many sessions per second—and flags it as an anomaly. The command output would show this host's source IP with anomaly type and session counts, confirming the botnet-like behavior.

  • ✗

    The FortiGate is under a DDoS attack

    Why it's wrong here

    A DDoS attack is typically distributed, involving many source IPs targeting a single victim, while the anomaly list entry described indicates a single source generating excessive outbound sessions. Although a volumetric attack might trigger some anomalies, the specific pattern of one host with many connections is more indicative of malware, not a distributed denial-of-service. The anomaly list focuses on per-source behavioral violations, not aggregate flood detection.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.