Courseiva

NSE4 System and Network Administration Practice Question

A company wants to ensure that administrative access to FortiGate is only allowed from the internal trusted network (192.168.1.0/24) and that all other access attempts are blocked. Which CLI command should the administrator configure first?

⚠ Common exam trap

It's easy for candidates to confuse `set allowaccess` (which enables protocols on an interface) with `set trusthost` (which restricts source IPs for admin login), leading them to select Option B thinking it controls who can access the device.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

config system admin; edit admin; set trusthost 192.168.1.0 255.255.255.0; end

The `config system admin` command with `set trusthost` restricts administrative login attempts to only the specified source IP address or subnet. By setting `trusthost 192.168.1.0 255.255.255.0`, the FortiGate will only allow admin access from the 192.168.1.0/24 network, blocking all other sources. This is the foundational step to enforce source-based access control for administrative interfaces.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    config system admin; edit admin; set trusthost 192.168.1.0 255.255.255.0; end

    Why this is correct

    The 'trusthost' command under 'config system admin' defines an allowed source IP or subnet for administrative logins to that specific admin account. By setting '192.168.1.0 255.255.255.0', only clients originating from the 192.168.1.0/24 network can authenticate as 'admin' — all other source IPs are rejected at the management daemon level, regardless of credentials. This is the only provided option that actually restricts administrative access to a specific source address range.

  • ✗

    config system interface; edit port1; set allowaccess ping https ssh; end

    Why it's wrong here

    This command configures the administrative protocols (ping, HTTPS, SSH) allowed on the physical interface port1. It does not limit which source IP addresses can initiate administrative sessions; any host that can reach port1's network can attempt an admin login. It is an interface-level service control, not a source-based access restriction. Without a 'trusthost' entry, an admin can log in from any reachable IP, so this does not achieve the stated 192.168.1.0/24 restriction.

  • ✗

    config system global; set admin-http-redirect enable; end

    Why it's wrong here

    Enabling 'admin-http-redirect' under 'config system global' only forces HTTP requests to the admin interface to be redirected to HTTPS for secure communication. It does not filter or restrict where administrative connections can originate. The setting merely changes the protocol behavior during login and has no effect on source IP validation, so it cannot ensure that only 192.168.1.0/24 users can access the FortiGate's admin functions.

  • ✗

    set admin-sport 443

    Why it's wrong here

    Executing 'set admin-sport 443' (presumably in 'config system global') changes the TCP port used for HTTPS administrative access from the default to 443 (or reasserts it). This modifies only the listening port — it does not inspect or restrict the source IP of incoming admin connections. As a result, it has no capability to limit administrative access to the 192.168.1.0/24 subnet, and the option is solely a port configuration, not a security policy.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.