Courseiva

NSE4 System and Network Administration Practice Question

You run 'diagnose sys session filter dport 443' and see the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate?

⚠ Common exam trap

It's easy for candidates to confuse 'duration' (time since session started) with 'expire' (time until session ends), leading candidates to incorrectly interpret the 3600 value as idle time or a port number.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The session is about to expire in 3599 seconds

The 'expire=3599' field indicates the session will be removed from the session table in 3599 seconds. The 'duration=3600' shows the session has been active for 3600 seconds, so the total session lifetime is 7200 seconds (3600 + 3599). This is a normal TCP session (proto=6) in state 01 (SYN_SENT), not an error or idle condition.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The session is in an error state

    Why it's wrong here

    proto_state=01 in FortiOS session output represents TCP state SYN_SENT, which is part of the normal three-way handshake after the initial SYN is sent. This is not an error indication; an error state would typically be reflected by a different code or by the session being in a teardown phase. Therefore, seeing proto_state=01 simply means the connection is in the setup phase, not that it has malfunctioned.

  • ✗

    The session has been idle for 3600 seconds

    Why it's wrong here

    The duration field in the diagnose sys session output records the total time since the session was first created, not the time since its last packet or byte activity. Idle time is a separate metric usually expressed as the timeout value or shown in the idle field. So a duration of 3600 seconds indicates the session has been alive for one hour, but it may still be actively passing traffic.

  • ✗

    The session is to port 3600

    Why it's wrong here

    The session filter was applied for destination port 443, so every displayed session shows dport=443. The number 3600 appears in the duration field, which is the session age in seconds, not a destination port. If the session were to port 3600, the filter would have been set for dport 3600, and the output would show that value instead. Thus, interpreting 3600 as a destination port contradicts the filter and the format of the output.

  • ✓

    The session is about to expire in 3599 seconds

    Why this is correct

    The expire field in FortiOS session output indicates the remaining time in seconds before the session entry is removed (i.e., its time-to-live). An expire value of 3599 seconds means the session still has approximately one hour of life left, not that it is expiring immediately. This value decreases as the session ages and is reset by traffic matching the session, so it reflects how much longer the session will be tracked if no further packets arrive.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.