Courseiva

NSE4 System and Network Administration Practice Question

A network administrator needs to configure a FortiGate to participate in SNMP monitoring. Which CLI command enables SNMP agent on the FortiGate?

⚠ Common exam trap

Candidates often confuse the FortiGate CLI syntax with Cisco IOS commands, where 'snmp-server enable' or 'snmp-server community' are used, leading them to select a similarly phrased but incorrect option like 'enable snmp service'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

config system snmp set status enable

The correct command to enable the SNMP agent on a FortiGate is 'config system snmp' followed by 'set status enable'. This enters the SNMP configuration context and activates the SNMP agent, which is required for the FortiGate to respond to SNMP queries from management systems. Without this command, the SNMP service remains disabled regardless of other SNMP settings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    config system snmp set status enable

    Why this is correct

    The valid FortiGate CLI sequence to turn on SNMP is navigating to the `config system snmp` branch and running `set status enable`. This `config` block manages the SNMP agent hosted on the FortiGate; `status enable` is the required toggle to start the agent. Issuing these commands enables SNMP to listen on the management interface and allows you to then configure SNMP communities, hosts, and trap receivers within the same configuration section.

  • ✗

    set system snmp enable

    Why it's wrong here

    `set system snmp enable` is malformed because FortiGate does not accept `set` as a global root command. The `set` verb is only valid inside a configuration block (e.g., inside `config system snmp`). The correct path always requires `config system snmp` followed by `set status enable`. Attempting to execute this line as a standalone command returns a CLI parser error, since there is no top-level object named `system snmp` to set.

  • ✗

    set snmp agent enable

    Why it's wrong here

    `set snmp agent enable` is not a valid FortiGate command because FortiGate does not model SNMP as an 'agent' resource in its CLI hierarchy. The SNMP functionality is configured under `config system snmp` and is toggled via the `status` keyword, not an `agent` keyword. This command would be unrecognized by the FortiGate CLI, as no such configuration node exists.

  • ✗

    enable snmp service

    Why it's wrong here

    `enable snmp service` is not valid FortiGate syntax. The FortiGate CLI does not use a generic `enable <service>` verb to turn on services; instead, each service has a specific configuration branch with a `status` setting. For SNMP, you must enter `config system snmp` and explicitly use `set status enable`. While the GUI uses a checkbox for SNMP, the CLI equivalent is exactly that config block, not a service-enable command.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.