Courseiva

NSE4 proto_state Practice Question

An administrator runs the following CLI command on a FortiGate: 'diagnose sys session filter dport 443' and sees output indicating sessions with proto_state=01 and duration=3600. What does this indicate about the sessions?

⚠ Common exam trap

The trap is to associate 'duration' with a timeout or TTL value, and to misinterpret 'proto_state=01' as established (state 6) rather than SYN_SENT (state 1).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The sessions are TCP connections in SYN state and have a timeout of 3600 seconds.

The command filters sessions on destination port 443. The output field 'proto_state=01' indicates a TCP session in SYN_SENT state (state 1), which is the initial step of a TCP handshake. The 'duration=3600' field shows that the session has been active for 3600 seconds (or represents a time value). Option B correctly identifies the state as TCP SYN and the number 3600 as a time value, making it the most accurate choice. Option A is wrong because UDP does not have a SYN state. Option C is wrong because state 01 is not established (established is state 06). Option D is wrong because ICMP does not use ports.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The sessions are UDP-based and have been active for 3600 seconds.

    Why it's wrong here

    Incorrect. 'proto_state=01' is a TCP state, not UDP. Also, duration is elapsed time, not a timeout.

  • ✓

    The sessions are TCP connections in SYN state and have a timeout of 3600 seconds.

    Why this is correct

    Correct. 'proto_state=01' corresponds to TCP SYN_SENT state, and duration=3600 means the session has been in that state for 3600 seconds.

  • ✗

    The sessions are TCP connections in established state with a duration of 3600 seconds.

    Why it's wrong here

    Incorrect. 'proto_state=01' is SYN_SENT, not established (which would be 06). Duration is elapsed time, not timeout.

  • ✗

    The sessions are ICMP packets with a TTL of 3600.

    Why it's wrong here

    Incorrect. ICMP sessions use a different protocol field; 'proto_state=01' is TCP-specific.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.