Courseiva

NSE4 System and Network Administration Practice Question

An administrator is setting up SNMP monitoring on a FortiGate. Which two configurations are necessary for a basic SNMP setup? (Choose two.)

⚠ Common exam trap

Candidates often confuse optional features like trap destinations or SNMPv3 authentication as mandatory for basic monitoring, when only the agent enablement and a community string are required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure an SNMP community with read-only access

An SNMP community with read-only access defines the basic authentication and access control for SNMPv1/v2c queries, which is essential for monitoring. Option C is correct because the SNMP agent must be enabled on the FortiGate to process SNMP requests from the monitoring server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a firewall policy to allow SNMP traffic from the monitoring server

    Why it's wrong here

    SNMP access to the FortiGate itself is managed via trusted hosts or local-in policies, not firewall policies. However, if the monitoring server is on a different subnet, a policy might be needed for the traffic to reach the FortiGate? Actually, SNMP is management traffic, so it is subject to administrative access controls (trusted hosts). A separate firewall policy is not required for management traffic.

  • ✓

    Configure an SNMP community with read-only access

    Why this is correct

    An SNMP community serves as the authentication credential for SNMPv1/v2c queries. Without a correctly configured community string, the FortiGate will silently discard SNMP requests, even if the agent is enabled and interfaces are available. Defining a community with read-only (RO) access allows the monitoring server to poll system statistics, interface counters, and other OIDs while preventing unauthorized configuration changes, which is the standard requirement for read-only monitoring scenarios.

  • ✓

    Enable the SNMP agent under System > SNMP

    Why this is correct

    The SNMP agent is the service process running on the FortiGate that listens for and responds to SNMP requests on the management interface. Enabling it under System > SNMP is the master switch: until this setting is enabled, the FortiGate will not answer any SNMP GET or GETNEXT messages, regardless of whether communities, hosts, or traps are defined. This is a distinct step from community configuration because it activates the protocol stack itself, and without it, a monitoring server will simply time out when attempting to poll the device.

  • ✗

    Set the SNMP trap destination IP

    Why it's wrong here

    Configuring an SNMP trap destination is neither required nor sufficient for enabling basic SNMP monitoring. A trap is an unsolicited, asynchronous notification sent by the agent to a manager (e.g., for interface down or CPU spike events), whereas typical monitoring relies on the manager actively polling the agent and receiving synchronous responses. Setting a trap destination only makes sense if you also define trap events under the appropriate settings, and it does not establish the read-only polling capability that is the core of SNMP monitoring. Therefore, omitting trap configuration leaves a working monitoring setup intact, while omitting the agent or community breaks it entirely.

  • ✗

    Configure a user for SNMPv3

    Why it's wrong here

    Configuring an SNMPv3 user is not a prerequisite for a *basic* SNMP setup, as FortiGate devices can utilise SNMPv1 or SNMPv2c, which only require a community string for access. This option is tempting because SNMPv3 provides robust authentication and encryption, essential for securing management traffic and preventing unauthorised access. It would be a necessary configuration if the question specified setting up SNMPv3 specifically, or if a secure, authenticated, and encrypted SNMP solution were required.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.