Courseiva

NSE4 System and Network Administration Practice Question

An administrator needs to allow management access to a FortiGate from the internal network only via HTTPS and SSH. The internal interface is named internal. Which configuration should the administrator apply?

⚠ Common exam trap

Candidates often confuse firewall policies with interface administrative access settings, thinking that a policy is needed to allow management traffic to the FortiGate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Under Network > Interfaces, edit the internal interface and enable HTTPS and SSH in the Administrative Access section.

Management access protocols are enabled per interface under Network > Interfaces by selecting the desired protocols in the Administrative Access section. This directly controls which protocols are allowed on that interface. Firewall policies, trusthost, and global settings do not enable management protocols on an interface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a firewall policy allowing HTTPS and SSH from the internal network to the FortiGate's internal IP address.

    Why it's wrong here

    Firewall policies control traffic passing through the FortiGate, not traffic destined to the FortiGate itself. Management access is controlled by the Administrative Access settings on the interface. A firewall policy would not permit management access unless the interface already allows it.

  • ✗

    Enable HTTPS and SSH under System > Settings and set the management port to the internal interface.

    Why it's wrong here

    System > Settings does not control per-interface management access. It contains global settings like the management port for the GUI, but not which interfaces allow HTTPS or SSH. Per-interface administrative access is configured under Network > Interfaces.

  • ✓

    Under Network > Interfaces, edit the internal interface and enable HTTPS and SSH in the Administrative Access section.

    Why this is correct

    Enabling HTTPS and SSH under Administrative Access on the internal interface allows management access from that network. This is the correct place to control which protocols are permitted for management on a per-interface basis. Other protocols remain disabled, meeting the requirement.

  • ✗

    Configure an admin user with a trusthost of the internal subnet and set the admin profile to allow HTTPS and SSH.

    Why it's wrong here

    Trusthost restricts which IP addresses an admin can log in from, but it does not enable the management protocols on the interface. The admin profile controls what the admin can do after login, not which protocols are available. Protocol access is still governed by interface settings.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.