NSE4 System and Network Administration Practice Question
An administrator is configuring a new FortiGate and wants to allow management access from the internal network via HTTPS. The internal interface is port2 with IP 192.168.1.1/24. Which CLI command correctly enables HTTPS administrative access on port2?
⚠ Common exam trap
Watch out — candidates often confuse the `allowaccess` parameter (which is set under `config system interface`) with global settings or firewall policies, mistakenly thinking that enabling HTTPS globally or in a policy will grant interface-specific management access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
config system interface edit port2 set allowaccess https end
The `config system interface` command is the proper context to set the `allowaccess` parameter, which controls the administrative protocols (such as HTTPS) permitted on a specific FortiGate interface. By editing port2 and setting `allowaccess https`, the administrator enables HTTPS management access on that interface, allowing internal users to reach the FortiGate's web GUI via 192.168.1.1.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
config firewall policy edit 1 set allowaccess https end
Why it's wrong here
The `config firewall policy` tree is used to define traffic-filtering rules between zones and interfaces, not to control administrative access. The `set allowaccess` parameter exists only on FortiGate interface objects, so placing it inside a firewall policy is syntactically invalid and would be rejected by the CLI. A firewall policy controls what traffic is allowed through the FortiGate, not which protocols can reach the management plane.
- ✓
config system interface edit port2 set allowaccess https end
Why this is correct
This is the correct method to enable HTTPS administrative access on a specific interface. The `config system interface` block enters the interface configuration context, `edit port2` selects the target interface, and `set allowaccess https` adds HTTPS to the list of management protocols permitted on that interface. Without this setting, even if the HTTPS daemon is globally enabled, FortiGate will ignore HTTPS connection attempts on port2 and the administrator would be locked out of that interface.
- ✗
config system admin edit admin set https enable end
Why it's wrong here
The `config system admin` tree manages administrator accounts, including their names, passwords, and trusthost restrictions, but it does not govern which interfaces allow management traffic. The `set https enable` command is not a valid parameter for an admin account; the administrative HTTPS service is a protocol-level setting, not a per-user privilege. Even if an admin is fully privileged, they still cannot reach the FortiGate unless the interface they connect through explicitly allows HTTPS.
- ✗
config system global set admin-https enable end
Why it's wrong here
The `config system global` tree contains global system-wide settings such as hostname or timeouts, but enabling HTTPS globally does not associate the service with a physical interface. The `set admin-https enable` command is not a real CLI parameter in FortiGate; administrative access is controlled per-interface via `set allowaccess`. Without enabling `allowaccess https` on the specific interface, the HTTPS service remains unreachable because the network interface filters management protocols before they reach the management daemon.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.