NSE4 Security Profiles Practice Question
You run the following CLI command on a FortiGate: diagnose sys session filter dport 443 diagnose sys session list The output shows many sessions with 'proto=6 proto_state=01 duration=3600 expire=3599'. What does this indicate about the traffic?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The sessions are in the SYN_SENT state and have not completed the three-way handshake
The proto=6 indicates TCP, and proto_state=01 indicates a TCP session in the SYN_SENT state (i.e., the three-way handshake is not complete). The long duration suggests these are half-open sessions, possibly indicating a SYN flood attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The sessions are fully established and idle
Why it's wrong here
The proto_state field in the FortiOS session table for these sessions is 01, which corresponds to SYN_SENT. A fully established and idle TCP session would display proto_state=02 (ESTABLISHED), indicating the three-way handshake completed and the connection is stable. Since the output shows 01, the sessions cannot be fully established.
- ✗
The sessions are for UDP traffic
Why it's wrong here
The protocol field in the diagnose sys session list shows proto=6, which is the IP protocol number for TCP (Transmission Control Protocol). UDP (User Datagram Protocol) is identified by protocol number 17. Therefore, these sessions are TCP, not UDP, and interpreting them as UDP traffic is incorrect.
- ✗
The sessions are being inspected by SSL deep inspection
Why it's wrong here
The session list generated by diagnose sys session does not contain any field that indicates SSL deep inspection status or proxy processing; it focuses on the underlying IP/TCP state. The proto_state=01 value indicates that the TCP handshake is still in progress, not that an SSL inspection profile is active. SSL inspection would be reflected in policy/profile counters, not in the session's proto_state field.
- ✓
The sessions are in the SYN_SENT state and have not completed the three-way handshake
Why this is correct
The proto_state=01 in the session table is interpreted as SYN_SENT, meaning the TCP handshake has not completed. The FortiGate has sent (or received) a SYN and is waiting for the corresponding SYN-ACK to move to ESTABLISHED (proto_state=02). Because the session remains in proto_state=01, it correctly indicates that the sessions are in the SYN_SENT state and have not completed the three-way handshake.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.