Courseiva

NSE7 Advanced Networking and SD-WAN Practice Question

You run 'diagnose sys session filter dport 443' and see the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?

⚠ Common exam trap

Many exam-takers confuse 'proto=6' with UDP or misinterpret 'proto_state=01' as a timeout indicator, when in fact it specifically denotes an established TCP session with a standard 1-hour idle timeout.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The session is a TCP session in established state that has been active for 1 hour and will expire in about 1 hour.

The output shows 'proto=6', which is the protocol number for TCP, and 'proto_state=01', which indicates the TCP session is in an established state (TCP_ESTABLISHED). The 'duration=3600' means the session has been active for 3600 seconds (1 hour), and 'expire=3599' means the session will expire in 3599 seconds (approximately 1 hour), consistent with the default TCP session timeout of 3600 seconds in FortiGate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The session is a UDP session with a short timeout.

    Why it's wrong here

    The output shows proto=6, which is TCP, so labelling it UDP contradicts the evidence. UDP sessions would display proto=17. The 3599-second expiry reflects the default TCP session timeout for established connections, not a short timeout. This option would fit only if the filter captured genuine UDP traffic, such as DNS on port 53.

  • ✗

    The session is a UDP session that has been active for 1 hour.

    Why it's wrong here

    The output shows proto=6, which is TCP, not UDP, so the protocol claim is wrong. UDP sessions display proto=17. This option tempts because UDP sessions also carry duration and expire values, and port 443 is commonly associated with QUIC over UDP, but the proto field alone settles the protocol here.

  • ✓

    The session is a TCP session in established state that has been active for 1 hour and will expire in about 1 hour.

    Why this is correct

    Proto 6 denotes TCP, and proto_state 01 confirms the established state. Duration 3600 shows the session has been active for one hour, while expire 3599 indicates roughly one hour remains before timeout. This matches the stem's requirement to interpret each field of the diagnose output accurately.

  • ✗

    The session is a TCP session that has timed out and is being removed.

    Why it's wrong here

    proto=6 denotes TCP, and expire=3599 shows the session still has roughly an hour remaining before removal, so it is active rather than timing out. A session genuinely being torn down would show expire at or near zero.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.