NSE4 System and Network Administration Practice Question
A FortiGate administrator needs to backup the configuration to a remote TFTP server. Which CLI command should be used?
⚠ Common exam trap
The trap here is that candidates familiar with Cisco IOS may mistakenly choose 'copy config tftp' (Option A) or 'backup configuration to tftp' (Option D), but FortiOS uses the 'execute' command structure and specific syntax 'backup config tftp' for this operation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
execute backup config tftp <filename> <tftp_server_ip>
The 'execute backup config tftp' command is the proper CLI syntax in FortiOS for backing up the current configuration to a remote TFTP server. This command triggers an immediate backup operation, and the filename and TFTP server IP are required parameters to specify the destination.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
copy config tftp <filename> <tftp_server_ip>
Why it's wrong here
The `copy config tftp` syntax is not recognized by FortiGate's CLI; it is a Cisco IOS-style command. FortiGate uses the `execute backup` keyword pair to initiate a configuration backup, while `copy` alone is reserved for file operations within the FortiGate filesystem. This command would return a syntax error because the CLI parser expects `execute` for administrative actions.
- ✗
execute restore config tftp <filename> <tftp_server_ip>
Why it's wrong here
The `execute restore config tftp` command performs the exact opposite of a backup: it downloads a configuration file from a TFTP server and overwrites the current running configuration. Using this command during a backup task would pull a remote config onto the device, potentially wiping the current settings and disrupting network operations. Since the goal is to export, not import, this command is incorrect.
- ✓
execute backup config tftp <filename> <tftp_server_ip>
Why this is correct
This is the correct command for backing up a FortiGate configuration to a TFTP server. The `execute backup` keyword pair is the standard CLI mechanism for exporting device state, and `config tftp` specifies the destination protocol and remote host. The filename argument is the remote file name to create on the TFTP server, followed by the server's IP, and this command will save the active configuration without altering the running system.
- ✗
backup configuration to tftp <tftp_server_ip>
Why it's wrong here
This command is invalid because it omits the mandatory `execute` verb that all FortiGate administrative actions require. Additionally, the phrasing `backup configuration to tftp` does not match the correct syntax, which uses the order `execute backup config tftp`. Without the `execute` keyword, the CLI interpreter treats it as an unrecognized statement and returns a syntax error, so it cannot perform the backup.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.