NSE4 System and Network Administration Practice Question
An administrator configures a FortiGate to use NTP for time synchronization. After configuration, the FortiGate still shows the wrong time. Which command should the administrator run to verify NTP status?
⚠ Common exam trap
A common mix-up: candidates confuse configuration commands (show system ntp) with diagnostic commands, or they assume a generic 'ntp status' command exists, when Fortinet specifically uses 'diagnose sys ntp status' for operational verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose sys ntp status
'diagnose sys ntp status' is the FortiGate CLI command that provides detailed NTP synchronization status, including whether the FortiGate is synchronized to an NTP server, the stratum level, and the last sync time. This command is specifically designed for troubleshooting NTP issues, unlike the other options which either show configuration or are invalid.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
show system ntp
Why it's wrong here
The 'show system ntp' command belongs to the FortiGate's configuration mode and prints the NTP-related settings currently stored in the running configuration, such as the NTP server addresses, authentication keys, and sync interval. It does not query the live NTP daemon or report the time source's reachability, stratum, or offset. These runtime sync statistics are only available through the diagnostic commands.
- ✗
execute ntp status
Why it's wrong here
The command 'execute ntp status' is not recognized in FortiOS; administrators often confuse it with the correct diagnostic command 'diagnose sys ntp status'. The 'execute' branch is reserved for administrative actions like ping, traceroute, or restoring factory defaults, not for status queries. To verify NTP synchronization, one must use the 'diagnose' branch, which provides the actual daemon status.
- ✗
diagnose sys time status
Why it's wrong here
'diagnose sys time status' is an invalid FortiOS command; the correct diagnostic command is 'diagnose sys ntp status'. The 'sys time' component exists for NTP configuration under 'config system ntp', but the diagnostic path for time sync status specifically uses 'ntp'. Typing this command will result in a 'Command fail. Return code -1' error rather than any time information.
- ✓
diagnose sys ntp status
Why this is correct
The 'diagnose sys ntp status' command is the correct FortiOS diagnostic to display the current NTP daemon runtime status. It reports whether NTP synchronization has been enabled, the IP address of the last selected NTP server, the synchronization status (e.g., synchronized or unsynchronized), and the measured time offset. This is the only command among the listed options that shows real-time NTP synchronization information, making it the correct answer.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.