Courseiva

NSE4 System and Network Administration Practice Question

You run the following diagnose command on a FortiGate and see the output:

diagnose sys session filter dport 443 diagnose sys session list

... proto=6 proto_state=01 duration=3600 expire=3599 ...

What does the 'proto_state=01' indicate?

⚠ Common exam trap

Watch out — candidates often confuse 'proto_state=01' with a fully established session because they see 'duration' and 'expire' values that look normal, not realizing that a half-open TCP session can still have a duration counter if the initial SYN was sent.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The session is in a half-open state (SYN_SENT)

In FortiGate session diagnostics, 'proto_state=01' for a TCP session (proto=6) indicates the session is in a half-open state, specifically SYN_SENT, meaning the initial SYN packet has been sent but the three-way handshake has not yet completed. This is a transient state before the session becomes fully established (proto_state=02).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The session is UDP, indicated by proto_state 01

    Why it's wrong here

    proto_state is a TCP-specific state field; UDP is connectionless and does not maintain a state machine like TCP, so it cannot be represented by proto_state=01. In the FortiGate session table, UDP traffic is identified by the protocol field (proto=17), while the proto_state for UDP is typically 00 or shown as a dash. Since proto_state=01 corresponds to TCP SYN_SENT, the session must be TCP, not UDP, so this interpretation is incorrect.

  • ✓

    The session is in a half-open state (SYN_SENT)

    Why this is correct

    proto_state=01 in a FortiGate session table represents TCP SYN_SENT, which occurs when a client has sent a SYN packet and is waiting for the server's SYN-ACK reply. This is a half-open state because the TCP three-way handshake has not yet completed; the connection is not fully established. If the handshake completes, the state advances to ESTABLISHED (06), so seeing 01 means the session is in the initial connection-attempt phase.

  • ✗

    The session has been fully established

    Why it's wrong here

    A fully established TCP session is in the ESTABLISHED state, which FortiGate records as proto_state=06, not 01. proto_state=01 indicates SYN_SENT, which is part of the three-way handshake initiation, meaning data transfer has not yet started. If the session had completed the handshake, the state would have progressed from 01 to a higher value such as 06, so the presence of 01 explicitly rules out an established connection.

  • ✗

    The session is being terminated

    Why it's wrong here

    TCP teardown phases like FIN_WAIT, CLOSE_WAIT, or TIME_WAIT have distinct numeric codes in the FortiGate session table (for example, 08 can indicate a close state); proto_state=01 does not correspond to any termination state. Instead, SYN_SENT is the very first step in connection establishment, occurring before any data flow. A session in the process of being terminated would show a FIN flag or a state like TIME_WAIT, not SYN_SENT, so this interpretation is incorrect.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.