Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.
The correct answer: B
In the first line "Session info: proto=6 proto_state=02"
Indicates TCP (proto=6) session in SYN_SENT state (proto=state=2)
https://kb.fortinet.com/kb/viewContent.do?externalId=FD30042
So this is A to me. Yes, proto_state=02 =SYN_SENT. However, with SYN_SENT, there's no 3-way handshake yet. In this evidence, we see traffic being sent and received, which doesn't work with SYN_SENT. Additionally, the expire timer is 3600s, which is default for ESTABLISHED. SYN_SENT has a default timer of 120s and it makes to sense to increase this.
Looks like a weirdly cobbled together output, but SYN_SENT zooms in on 1 piece of evidence while ignoring everything that contradicts it.
upvoted 3 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
phototrait
Highly Voted 2 years, 9 months agobrld
Highly Voted 2 years, 9 months agoIbrahimadwan
Most Recent 11 months, 1 week agolearner_88
1 year, 6 months agojohnnd
1 year, 7 months agojmanning
1 year, 8 months agoPascalCert
1 year, 9 months agoGoshler
1 year, 9 months agoBluey
1 year, 9 months ago