NSE4 System and Network Administration Practice Question
A FortiGate administrator needs to allow SSH management access from a specific IP address 10.0.0.100. Which configuration is required?
⚠ Common exam trap
Many exam-takers confuse firewall policies (which control transit traffic) with administrative access controls (which control traffic destined to the FortiGate itself), leading them to incorrectly select option D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the trusted host for the admin account to 10.0.0.100
FortiGate uses the 'trusted host' feature to restrict administrative access to specific source IP addresses. By setting the trusted host to 10.0.0.100 for the admin account, only that IP can initiate SSH sessions to the FortiGate management interface, regardless of which interface SSH is enabled on.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable SSH on the WAN interface and allow all IPs
Why it's wrong here
Enabling SSH on the WAN interface with all IPs allowed does not restrict access to a single source; it opens the management daemon to the entire internet, drastically increasing the attack surface. Even if the admin account has a trusted host, the interface-level access still accepts connection attempts from any source, and trusted-host enforcement is applied at the admin level, not as a network-layer filter. This approach fails to satisfy the requirement of allowing only 10.0.0.100 and is a major security risk.
- ✓
Set the trusted host for the admin account to 10.0.0.100
Why this is correct
Setting the trusted host for the admin account to 10.0.0.100 is the correct method because FortiGate's trusted-host feature restricts administrative logins to traffic originating from that exact source IP address. When configured, the SSH management daemon will reject authentication attempts from any other IP, regardless of which interfaces have SSH enabled. This provides a precise, per-admin source-IP allowlist that directly matches the requirement to permit only one specific management host.
- ✗
Configure an access list on the upstream router
Why it's wrong here
An access list on an upstream router is external to FortiGate and only filters traffic before it reaches the device; it does not enforce FortiGate's own administrative security controls. The requirement is to restrict management access on the FortiGate itself, so relying on an external ACL is fragile, especially if management traffic can arrive via multiple paths or interfaces. Additionally, the ACL would be managed outside the FortiGate, leaving a gap in the security posture if not consistently updated.
- ✗
Create a firewall policy allowing SSH from 10.0.0.100 to the FortiGate
Why it's wrong here
Creating a firewall policy allowing SSH from 10.0.0.100 to the FortiGate is invalid because standard firewall policies govern traffic transiting the FortiGate between its interfaces, not traffic destined to the FortiGate's own management plane. Management access is controlled by admin configuration, including trusted hosts and the local-in policy, which are separate from the forward-traffic policy table. A firewall policy would not affect which source IPs are allowed to reach the SSH daemon, so it would not achieve the desired restriction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.