Courseiva

NSE4 System and Network Administration Practice Question

A FortiGate administrator needs to allow SSH management access from a specific IP address 10.0.0.100. Which configuration is required?

⚠ Common exam trap

Many exam-takers confuse firewall policies (which control transit traffic) with administrative access controls (which control traffic destined to the FortiGate itself), leading them to incorrectly select option D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the trusted host for the admin account to 10.0.0.100

FortiGate uses the 'trusted host' feature to restrict administrative access to specific source IP addresses. By setting the trusted host to 10.0.0.100 for the admin account, only that IP can initiate SSH sessions to the FortiGate management interface, regardless of which interface SSH is enabled on.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable SSH on the WAN interface and allow all IPs

    Why it's wrong here

    Enabling SSH on the WAN interface with all IPs allowed does not restrict access to a single source; it opens the management daemon to the entire internet, drastically increasing the attack surface. Even if the admin account has a trusted host, the interface-level access still accepts connection attempts from any source, and trusted-host enforcement is applied at the admin level, not as a network-layer filter. This approach fails to satisfy the requirement of allowing only 10.0.0.100 and is a major security risk.

  • ✓

    Set the trusted host for the admin account to 10.0.0.100

    Why this is correct

    Setting the trusted host for the admin account to 10.0.0.100 is the correct method because FortiGate's trusted-host feature restricts administrative logins to traffic originating from that exact source IP address. When configured, the SSH management daemon will reject authentication attempts from any other IP, regardless of which interfaces have SSH enabled. This provides a precise, per-admin source-IP allowlist that directly matches the requirement to permit only one specific management host.

  • ✗

    Configure an access list on the upstream router

    Why it's wrong here

    An access list on an upstream router is external to FortiGate and only filters traffic before it reaches the device; it does not enforce FortiGate's own administrative security controls. The requirement is to restrict management access on the FortiGate itself, so relying on an external ACL is fragile, especially if management traffic can arrive via multiple paths or interfaces. Additionally, the ACL would be managed outside the FortiGate, leaving a gap in the security posture if not consistently updated.

  • ✗

    Create a firewall policy allowing SSH from 10.0.0.100 to the FortiGate

    Why it's wrong here

    Creating a firewall policy allowing SSH from 10.0.0.100 to the FortiGate is invalid because standard firewall policies govern traffic transiting the FortiGate between its interfaces, not traffic destined to the FortiGate's own management plane. Management access is controlled by admin configuration, including trusted hosts and the local-in policy, which are separate from the forward-traffic policy table. A firewall policy would not affect which source IPs are allowed to reach the SSH daemon, so it would not achieve the desired restriction.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.