NSE7 Troubleshooting and Diagnostics Practice Question
You run 'diagnose sys session filter dport 443' and see sessions with a duration of 7200 seconds and expire time of 3600 seconds. What does this indicate?
⚠ Common exam trap
Candidates often confuse 'duration' with 'idle time' — candidates often assume duration measures inactivity, but FortiGate's session table uses separate fields for idle time and total session age.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The session has been alive for 7200 seconds and will expire in 3600 seconds
The 'duration' field in the 'diagnose sys session filter' output shows how long the session has been active (7200 seconds), while the 'expire' field indicates the remaining time before the session times out (3600 seconds). Option C correctly interprets both values. This is standard FortiGate session table behavior, where each session has a configurable timeout (e.g., default TCP timeout is 3600 seconds for established sessions).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The session has been idle for 7200 seconds
Why it's wrong here
Duration is total session age since creation, not idle time. It tempts because both counters measure time, but idle time is tracked separately; a 7200-second duration with 3600 seconds remaining means the session is still active.
- ✗
The session helper is interfering with the session
Why it's wrong here
A session helper affects protocol handling such as FTP or SIP, not the relationship between duration and expire time. It tempts because helpers can alter session behaviour, but these counters simply reflect age and remaining timeout.
- ✓
The session has been alive for 7200 seconds and will expire in 3600 seconds
Why this is correct
Session duration counts elapsed time since establishment, while expire time counts remaining seconds before teardown. A duration of 7200 with expire time of 3600 therefore means the session has existed for two hours and will close in one more.
- ✗
The session has already expired
Why it's wrong here
Expire time is the remaining seconds before the session times out, not a signal that it has already expired. It tempts because a positive expire time can be misread as elapsed; an expired session would be removed from the session table.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.