NSE4 proto_state Practice Question
An administrator runs the following CLI command on a FortiGate: 'diagnose sys session filter dport 443' and sees output indicating sessions with proto_state=01 and duration=3600. What does this indicate about the sessions?
⚠ Common exam trap
The trap is to associate 'duration' with a timeout or TTL value, and to misinterpret 'proto_state=01' as established (state 6) rather than SYN_SENT (state 1).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The sessions are TCP connections in SYN state and have a timeout of 3600 seconds.
The command filters sessions on destination port 443. The output field 'proto_state=01' indicates a TCP session in SYN_SENT state (state 1), which is the initial step of a TCP handshake. The 'duration=3600' field shows that the session has been active for 3600 seconds (or represents a time value). Option B correctly identifies the state as TCP SYN and the number 3600 as a time value, making it the most accurate choice. Option A is wrong because UDP does not have a SYN state. Option C is wrong because state 01 is not established (established is state 06). Option D is wrong because ICMP does not use ports.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The sessions are UDP-based and have been active for 3600 seconds.
Why it's wrong here
Incorrect. 'proto_state=01' is a TCP state, not UDP. Also, duration is elapsed time, not a timeout.
- ✓
The sessions are TCP connections in SYN state and have a timeout of 3600 seconds.
Why this is correct
Correct. 'proto_state=01' corresponds to TCP SYN_SENT state, and duration=3600 means the session has been in that state for 3600 seconds.
- ✗
The sessions are TCP connections in established state with a duration of 3600 seconds.
Why it's wrong here
Incorrect. 'proto_state=01' is SYN_SENT, not established (which would be 06). Duration is elapsed time, not timeout.
- ✗
The sessions are ICMP packets with a TTL of 3600.
Why it's wrong here
Incorrect. ICMP sessions use a different protocol field; 'proto_state=01' is TCP-specific.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.