NSE7 Enterprise Firewall and VDOMs Practice Question
An admin runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate?
⚠ Common exam trap
Candidates often confuse `proto_state=01` with a blocking state or a handshake-in-progress state, when in fact it specifically indicates an established TCP connection in Fortinet's session table.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The session is established and has been active for 1 hour
The output shows `proto=6` (TCP), `proto_state=01` (ESTABLISHED in Fortinet's session table), `duration=3600` seconds (1 hour), and `expire=3599` seconds (remaining lifetime). This combination indicates a fully established TCP session that has been active for one hour and is still valid, not blocked or in a transitional state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The session is being blocked by a firewall policy
Why it's wrong here
proto_state=01 indicates an established session, and the duration with a matching expiry shows it is active and being tracked, not blocked. It is tempting because a filtered port 443 session could imply policy denial, and would be correct if the output showed a deny state or no session entry.
- ✗
The session is in SYN_SENT state, waiting for a reply
Why it's wrong here
proto_state=01 denotes the established state for TCP, not SYN_SENT, which would show proto_state=02. The session has already completed the three-way handshake and is passing traffic, with duration 3600 and expire 3599 indicating an active, refreshed session nearing its timeout.
- ✓
The session is established and has been active for 1 hour
Why this is correct
The `proto_state=01` value confirms an established TCP session, while `duration=3600` records 3600 seconds of activity — exactly one hour. The `expire=3599` counter shows the session is being refreshed, satisfying the stem's requirement to interpret an active, long-lived connection rather than a closing or idle one.
- ✗
The session is in TIME_WAIT state after a FIN
Why it's wrong here
proto_state=01 denotes a session in the established state, not TIME_WAIT; TIME_WAIT follows a FIN exchange and appears with different state values. It is tempting because a long duration with expire nearly equal to it can suggest teardown, and would be correct if the output showed the session closing.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.