Courseiva

NSE4 System and Network Administration Practice Question

A FortiGate administrator wants to synchronize the system time with an external NTP server. Which CLI command should be used to configure the NTP server?

⚠ Common exam trap

Test-takers frequently confuse `config system ntp` with `config system global` because both are under the `config system` hierarchy, but NTP configuration has its own dedicated subcommand and is not a global setting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

config system ntp

The `config system ntp` command enters the NTP configuration context in FortiOS, where you can specify NTP servers, authentication, and synchronization settings. This is the standard CLI path for configuring NTP on FortiGate devices, as opposed to other commands that only display status or set the date manually.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    execute date

    Why it's wrong here

    The 'execute date' command manually sets the system date and time on the FortiGate. This is a one-time override, not a persistent configuration mechanism. It does not establish any NTP server relationship or enable periodic synchronization, so it cannot be used to keep the device clock aligned automatically with time sources.

  • ✗

    diagnose ntp status

    Why it's wrong here

    The 'diagnose ntp status' command queries and displays the current NTP employment state, such as reachability, jitter, and last synchronization status. It is strictly a diagnostic and verification tool, providing insight into NTP operation after configuration. It cannot modify any NTP settings, add servers, or change synchronization behavior, making it irrelevant for initial NTP setup.

  • ✓

    config system ntp

    Why this is correct

    The 'config system ntp' command enters the NTP configuration subtree, which is the correct place on a FortiGate to define NTP servers and enable automatic time synchronization. Under this hierarchy, administrators can set primary and secondary NTP server addresses, configure poll intervals, and optionally configure authentication keys. This persistent configuration is what the FortiGate uses to continuously sync its system clock, fulfilling the requirement to synchronize time via NTP.

  • ✗

    config system global

    Why it's wrong here

    The 'config system global' command provides access to device-wide settings like hostname, timezone, and administrative options, but NTP server configuration is not part of this subtree. While you can set the timezone and daylight-saving rules here, that only handles offset adjustments, not actual time synchronization from an external source. To add NTP servers, you must enter the separate 'config system ntp' mode, so using 'config system global' cannot achieve NTP-based time sync.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.