Courseiva

NSE4 System and Network Administration Practice Question

An administrator configures a FortiGate to use NTP for time synchronization. After configuration, the FortiGate still shows the wrong time. Which command should the administrator run to verify NTP status?

⚠ Common exam trap

A common mix-up: candidates confuse configuration commands (show system ntp) with diagnostic commands, or they assume a generic 'ntp status' command exists, when Fortinet specifically uses 'diagnose sys ntp status' for operational verification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose sys ntp status

'diagnose sys ntp status' is the FortiGate CLI command that provides detailed NTP synchronization status, including whether the FortiGate is synchronized to an NTP server, the stratum level, and the last sync time. This command is specifically designed for troubleshooting NTP issues, unlike the other options which either show configuration or are invalid.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    show system ntp

    Why it's wrong here

    The 'show system ntp' command belongs to the FortiGate's configuration mode and prints the NTP-related settings currently stored in the running configuration, such as the NTP server addresses, authentication keys, and sync interval. It does not query the live NTP daemon or report the time source's reachability, stratum, or offset. These runtime sync statistics are only available through the diagnostic commands.

  • ✗

    execute ntp status

    Why it's wrong here

    The command 'execute ntp status' is not recognized in FortiOS; administrators often confuse it with the correct diagnostic command 'diagnose sys ntp status'. The 'execute' branch is reserved for administrative actions like ping, traceroute, or restoring factory defaults, not for status queries. To verify NTP synchronization, one must use the 'diagnose' branch, which provides the actual daemon status.

  • ✗

    diagnose sys time status

    Why it's wrong here

    'diagnose sys time status' is an invalid FortiOS command; the correct diagnostic command is 'diagnose sys ntp status'. The 'sys time' component exists for NTP configuration under 'config system ntp', but the diagnostic path for time sync status specifically uses 'ntp'. Typing this command will result in a 'Command fail. Return code -1' error rather than any time information.

  • ✓

    diagnose sys ntp status

    Why this is correct

    The 'diagnose sys ntp status' command is the correct FortiOS diagnostic to display the current NTP daemon runtime status. It reports whether NTP synchronization has been enabled, the IP address of the last selected NTP server, the synchronization status (e.g., synchronized or unsynchronized), and the measured time offset. This is the only command among the listed options that shows real-time NTP synchronization information, making it the correct answer.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.