NSE4 System and Network Administration Practice Question
You run the following diagnose command on a FortiGate and see the output:
diagnose sys session filter dport 443 diagnose sys session list
... proto=6 proto_state=01 duration=3600 expire=3599 ...
What does the 'proto_state=01' indicate?
⚠ Common exam trap
Watch out — candidates often confuse 'proto_state=01' with a fully established session because they see 'duration' and 'expire' values that look normal, not realizing that a half-open TCP session can still have a duration counter if the initial SYN was sent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The session is in a half-open state (SYN_SENT)
In FortiGate session diagnostics, 'proto_state=01' for a TCP session (proto=6) indicates the session is in a half-open state, specifically SYN_SENT, meaning the initial SYN packet has been sent but the three-way handshake has not yet completed. This is a transient state before the session becomes fully established (proto_state=02).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The session is UDP, indicated by proto_state 01
Why it's wrong here
proto_state is a TCP-specific state field; UDP is connectionless and does not maintain a state machine like TCP, so it cannot be represented by proto_state=01. In the FortiGate session table, UDP traffic is identified by the protocol field (proto=17), while the proto_state for UDP is typically 00 or shown as a dash. Since proto_state=01 corresponds to TCP SYN_SENT, the session must be TCP, not UDP, so this interpretation is incorrect.
- ✓
The session is in a half-open state (SYN_SENT)
Why this is correct
proto_state=01 in a FortiGate session table represents TCP SYN_SENT, which occurs when a client has sent a SYN packet and is waiting for the server's SYN-ACK reply. This is a half-open state because the TCP three-way handshake has not yet completed; the connection is not fully established. If the handshake completes, the state advances to ESTABLISHED (06), so seeing 01 means the session is in the initial connection-attempt phase.
- ✗
The session has been fully established
Why it's wrong here
A fully established TCP session is in the ESTABLISHED state, which FortiGate records as proto_state=06, not 01. proto_state=01 indicates SYN_SENT, which is part of the three-way handshake initiation, meaning data transfer has not yet started. If the session had completed the handshake, the state would have progressed from 01 to a higher value such as 06, so the presence of 01 explicitly rules out an established connection.
- ✗
The session is being terminated
Why it's wrong here
TCP teardown phases like FIN_WAIT, CLOSE_WAIT, or TIME_WAIT have distinct numeric codes in the FortiGate session table (for example, 08 can indicate a close state); proto_state=01 does not correspond to any termination state. Instead, SYN_SENT is the very first step in connection establishment, occurring before any data flow. A session in the process of being terminated would show a FIN flag or a state like TIME_WAIT, not SYN_SENT, so this interpretation is incorrect.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.