Courseiva
Security Profiles →hardMultiple Choice

NSE4 Security Profiles Practice Question

You run the following CLI command on a FortiGate: diagnose sys session filter dport 443 diagnose sys session list The output shows many sessions with 'proto=6 proto_state=01 duration=3600 expire=3599'. What does this indicate about the traffic?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The sessions are in the SYN_SENT state and have not completed the three-way handshake

The proto=6 indicates TCP, and proto_state=01 indicates a TCP session in the SYN_SENT state (i.e., the three-way handshake is not complete). The long duration suggests these are half-open sessions, possibly indicating a SYN flood attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The sessions are fully established and idle

    Why it's wrong here

    The proto_state field in the FortiOS session table for these sessions is 01, which corresponds to SYN_SENT. A fully established and idle TCP session would display proto_state=02 (ESTABLISHED), indicating the three-way handshake completed and the connection is stable. Since the output shows 01, the sessions cannot be fully established.

  • ✗

    The sessions are for UDP traffic

    Why it's wrong here

    The protocol field in the diagnose sys session list shows proto=6, which is the IP protocol number for TCP (Transmission Control Protocol). UDP (User Datagram Protocol) is identified by protocol number 17. Therefore, these sessions are TCP, not UDP, and interpreting them as UDP traffic is incorrect.

  • ✗

    The sessions are being inspected by SSL deep inspection

    Why it's wrong here

    The session list generated by diagnose sys session does not contain any field that indicates SSL deep inspection status or proxy processing; it focuses on the underlying IP/TCP state. The proto_state=01 value indicates that the TCP handshake is still in progress, not that an SSL inspection profile is active. SSL inspection would be reflected in policy/profile counters, not in the session's proto_state field.

  • ✓

    The sessions are in the SYN_SENT state and have not completed the three-way handshake

    Why this is correct

    The proto_state=01 in the session table is interpreted as SYN_SENT, meaning the TCP handshake has not completed. The FortiGate has sent (or received) a SYN and is waiting for the corresponding SYN-ACK to move to ESTABLISHED (proto_state=02). Because the session remains in proto_state=01, it correctly indicates that the sessions are in the SYN_SENT state and have not completed the three-way handshake.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.