nerdexam
Fortinet

FCSS_NST_SE-7.4 · Question #54

Refer to the exhibit, which shows the partial output of a diagnose command. Which two conclusions can you draw from the output shown in the exhibit? (Choose two.)

The correct answer is A. FortiGate will drop the expected traffic if it does not arrive within 23 seconds. C. This is a pinhole session to allow traffic for a TCP protocol that dynamically assigns TCP ports. The "expire=23" value shows this expectation entry will be removed - and any matching packets subsequently dropped - if the expected traffic doesn't arrive within 23 seconds. Because it's a TCP-based expectation entry (proto=6) set up to allow dynamically assigned ports, it's…

Packet Flow and Session Management

Question

Refer to the exhibit, which shows the partial output of a diagnose command. Which two conclusions can you draw from the output shown in the exhibit? (Choose two.)

Exhibit

FCSS_NST_SE-7.4 question #54 exhibit

Options

  • AFortiGate will drop the expected traffic if it does not arrive within 23 seconds.
  • BClearing the master session has no impact on the expectation session.
  • CThis is a pinhole session to allow traffic for a TCP protocol that dynamically assigns TCP ports.
  • DThe session is checked against firewall policy ID 25.

How the community answered

(58 responses)
  • A
    81% (47)
  • B
    7% (4)
  • D
    12% (7)

Explanation

The "expire=23" value shows this expectation entry will be removed - and any matching packets subsequently dropped - if the expected traffic doesn't arrive within 23 seconds. Because it's a TCP-based expectation entry (proto=6) set up to allow dynamically assigned ports, it's acting as a pinhole session for a protocol that opens ephemeral TCP ports.

Topics

#expectation session#pinhole session#session table#dynamic port allocation

Community Discussion

No community discussion yet for this question.

Full FCSS_NST_SE-7.4 Practice