An administrator wants to upgrade the FortiOS firmware on a FortiGate. Which step is critical before starting the upgrade process?
Backing up the configuration file is the correct and mandatory prerequisite before upgrading FortiOS. Use the 'execute backup config' CLI command or the GUI's System > Backup feature to save a copy of the current configuration to a local host or remote server. If the upgrade fails or you need to downgrade to a previous firmware version, this backup allows you to restore the exact pre-upgrade settings, preventing configuration loss or manual re-entry of policies, routes, and objects.
Why this answer
Backing up the configuration file is critical before upgrading FortiOS because the upgrade process may fail or corrupt the configuration, and a backup ensures you can restore the FortiGate to its previous operational state. Without a valid backup, a failed upgrade could result in a complete loss of configuration, requiring manual reconfiguration or a factory reset. Fortinet recommends always backing up the configuration before any firmware upgrade to mitigate risks.
Exam trap
The trap here is that candidates may confuse operational steps (like clearing sessions or disabling policies) with the critical prerequisite of configuration backup, assuming the upgrade process will automatically preserve settings without risk.
How to eliminate wrong answers
Option A is wrong because rebooting the FortiGate before an upgrade is unnecessary and may disrupt current operations; the upgrade process itself handles rebooting as needed. Option B is wrong because clearing all sessions is not a prerequisite for upgrading; the FortiGate will terminate sessions during the reboot phase of the upgrade automatically. Option D is wrong because disabling all firewall policies is not required; the upgrade process preserves policy configurations, and disabling them could cause unintended traffic disruptions if the upgrade fails or is rolled back.