NSE4 System and Network Administration Practice Question
A FortiGate administrator configures SNMPv2c on the FortiGate to send traps to a monitoring server. However, no traps are received. The monitoring server can ping the FortiGate. What is the MOST likely cause?
⚠ Common exam trap
Candidates often assume SNMP traps are blocked by a firewall policy, but since traps are initiated by the FortiGate (outbound), the server's ability to ping the FortiGate confirms Layer 3 reachability, shifting the focus to authentication or receiver configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SNMP community string does not match between FortiGate and server.
SNMPv2c uses community strings as a form of authentication. If the community string configured on the FortiGate does not match the one configured on the monitoring server, the server will reject the trap. Since the server can ping the FortiGate, network connectivity is fine, and the issue is most likely an authentication mismatch.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SNMPv2c is not supported on FortiGate; only v3 is supported.
Why it's wrong here
FortiGate fully supports SNMPv2c, as well as v1 and v3, so this option is incorrect. SNMPv2c relies on a community string for authentication, and FortiGate allows configuring community strings for both SNMP queries and trap transmissions. A missing or misconfigured community string is the classic cause of traps being sent but not displayed by the monitoring station.
- ✗
The FortiGate's firewall policy blocks SNMP traffic from the monitoring server.
Why it's wrong here
Since traps are outbound from FortiGate to the monitoring server on UDP 162, a firewall policy on FortiGate blocking traffic from the monitoring server would be irrelevant. FortiGate's local-out traffic is generally allowed unless a local-out policy explicitly denies it; the default is to permit such traffic. Even if an inbound policy were blocking, the traps would be generated and sent, so this cannot explain the server receiving nothing if other destinations are valid.
- ✓
The SNMP community string does not match between FortiGate and server.
Why this is correct
In SNMPv2c, the community string operates as a shared secret in each PDU, and the trap receiver uses it to validate the message. If the community string configured for trap sending on FortiGate does not match what the monitoring server expects, the server will silently discard the trap without any response, since SNMP uses UDP. The FortiGate will continue to show the trap as sent, so the administrator sees a successful configuration but no trap arrives at the monitoring station. This mismatch is the most common reason for traps not appearing when network connectivity and receiver IP are correct.
- ✗
The monitoring server's IP is not in the SNMP trap receiver list on FortiGate.
Why it's wrong here
If the monitoring server's IP were not listed in the trap receiver list, FortiGate would not send the trap at all, resulting in no traffic reaching that server. In the described scenario, traps may be sent to the correct IP but are rejected at the application layer, implying the receiver list already contains that IP. Thus, while an incorrect receiver list is a plausible cause, it is less specific than a community mismatch because it would prevent transmission, not just authentication.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.