Courseiva

FortiGate SNMP Configuration for Read-Only Monitoring

A FortiGate administrator needs to allow SNMP monitoring from a management station at 10.10.10.50. Which TWO configuration steps are required? (Choose two.)

⚠ Common exam trap

Candidates often confuse SNMP monitoring (polling) with SNMP traps, or mistakenly think a firewall policy is needed for local management traffic, when in fact SNMP agent access is controlled entirely by the community configuration and the global enable setting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable SNMP agent globally

The SNMP agent must be globally enabled on the FortiGate before any SNMP queries can be processed. Option B is correct because an SNMP community with read-only access defines the authentication and access control parameters, and restricting it to 10.10.10.50 ensures only that management station can poll the device.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable SNMP agent globally

    Why this is correct

    The FortiGate's SNMP agent is disabled by default; without enabling it globally under System > SNMP, the device will not respond to any SNMP get/set requests regardless of other configuration. Enabling the agent is the mandatory first step to allow a management station to poll MIB objects such as interface utilization, CPU, and memory. This is a global toggle, not per-interface, and once enabled the agent listens on port 161 for all configured SNMP communities.

  • ✓

    Configure an SNMP community with read-only access and restrict access to 10.10.10.50

    Why this is correct

    An SNMP community string acts like a password for v1/v2c; for monitoring you should set read-only (RO) permission to prevent remote configuration via SNMP sets. Restricting the community to a specific management host IP (10.10.10.50) via the 'Allow Hosts' setting ensures that only that station can poll the FortiGate, mitigating the risk of unauthorized access. Without this restriction, any host that knows the community string could query the entire MIB tree.

  • ✗

    Configure an SNMP trap to send alerts to 10.10.10.50

    Why it's wrong here

    SNMP traps are asynchronous notifications generated by the FortiGate (e.g., interface down, high CPU) and are pushed to the NMS on UDP port 162; they do not fulfill a polling-based monitoring model. If the management station is configured to poll the FortiGate using GET requests, configuring a trap is irrelevant to answering those queries, and the FortiGate will still remain unresponsive to polls unless the agent is enabled and a community is configured. Traps are a complementary feature to notify the NMS of events, but not a substitute for enabling the agent.

  • ✗

    Enable SNMP on the interface connected to the management station

    Why it's wrong here

    FortiGate's SNMP access is not enabled per-interface like HTTP or SSH administrative access; the SNMP agent listens globally and access is filtered using the community's allowed-host IP list. Even if you enable SNMP on an interface (which isn't an actual option in the GUI for SNMP), the device would still not respond unless the global agent is enabled and a community is configured with appropriate trusted hosts. Therefore, this setting alone is neither necessary nor sufficient for allowing the management station to poll.

  • ✗

    Configure a firewall policy allowing SNMP from the management station

    Why it's wrong here

    Firewall policies control traffic forwarded between FortiGate's interfaces, but traffic destined to the FortiGate itself (such as SNMP queries to the management IP) is governed by the administrative access settings in the network interface configuration and the SNMP community's trusted host list. Since the FortiGate is the management target, not forwarding traffic to a third party, a firewall policy will not open the SNMP port; Instead, you must enable admin access for SNMP (where applicable) and define a community with the management station as allowed host. In many firmware versions, SNMP is not part of the interface admin access flags, further showing that policy is the wrong mechanism.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.