Courseiva

NSE7 Troubleshooting and Diagnostics Practice Question

You run 'diagnose sys session filter dport 443' and see sessions with a duration of 7200 seconds and expire time of 3600 seconds. What does this indicate?

⚠ Common exam trap

Candidates often confuse 'duration' with 'idle time' — candidates often assume duration measures inactivity, but FortiGate's session table uses separate fields for idle time and total session age.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The session has been alive for 7200 seconds and will expire in 3600 seconds

The 'duration' field in the 'diagnose sys session filter' output shows how long the session has been active (7200 seconds), while the 'expire' field indicates the remaining time before the session times out (3600 seconds). Option C correctly interprets both values. This is standard FortiGate session table behavior, where each session has a configurable timeout (e.g., default TCP timeout is 3600 seconds for established sessions).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The session has been idle for 7200 seconds

    Why it's wrong here

    Duration is total session age since creation, not idle time. It tempts because both counters measure time, but idle time is tracked separately; a 7200-second duration with 3600 seconds remaining means the session is still active.

  • ✗

    The session helper is interfering with the session

    Why it's wrong here

    A session helper affects protocol handling such as FTP or SIP, not the relationship between duration and expire time. It tempts because helpers can alter session behaviour, but these counters simply reflect age and remaining timeout.

  • ✓

    The session has been alive for 7200 seconds and will expire in 3600 seconds

    Why this is correct

    Session duration counts elapsed time since establishment, while expire time counts remaining seconds before teardown. A duration of 7200 with expire time of 3600 therefore means the session has existed for two hours and will close in one more.

  • ✗

    The session has already expired

    Why it's wrong here

    Expire time is the remaining seconds before the session times out, not a signal that it has already expired. It tempts because a positive expire time can be misread as elapsed; an expired session would be removed from the session table.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.