Courseiva

NSE4 System and Network Administration Practice Question

An administrator needs to back up the FortiGate configuration to a TFTP server at 10.0.0.10. Which command should be used?

⚠ Common exam trap

Watch out — candidates often confuse the FortiGate CLI syntax with a standard TFTP client command (Option A) or mistakenly use 'ftp' (Option C) instead of 'tftp', overlooking the specific protocol required by the server.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

execute backup config tftp mybackup.conf 10.0.0.10

The correct command to back up a FortiGate configuration to a TFTP server is 'execute backup config tftp <filename> <server-ip>'. This is a standard FortiOS CLI command that uses TFTP (Trivial File Transfer Protocol) to transfer the configuration file to the specified server at 10.0.0.10. Option B matches this syntax exactly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    tftp -p -l mybackup.conf 10.0.0.10

    Why it's wrong here

    This is a standard Unix/Linux TFTP client command, not a FortiGate CLI command. On FortiGate, you must use the 'execute' command hierarchy; a bare 'tftp' binary is not available in the FortiGate CLI environment. Even if it were, the -p and -l flags are for a client push, not the FortiGate's backup operation syntax.

  • ✓

    execute backup config tftp mybackup.conf 10.0.0.10

    Why this is correct

    This is the correct FortiGate CLI command for backing up the configuration to a TFTP server. The command 'execute backup config' specifies the backup operation, 'tftp' selects the protocol, 'mybackup.conf' is the destination filename on the server, and '10.0.0.10' is the server IP. On FortiGate, this initiates a TFTP put from the unit, and it is the exact syntax required to meet the administrator's need.

  • ✗

    execute backup config ftp mybackup.conf 10.0.0.10

    Why it's wrong here

    This command would attempt the backup over FTP instead of TFTP, which is the wrong protocol per the requirement. Moreover, an FTP backup on FortiGate generally requires additional credential parameters (username and password) to authenticate to the FTP server; without them, the command is incomplete and would likely fail even if FTP were acceptable. The presence of 'ftp' instead of 'tftp' changes the entire operation.

  • ✗

    copy config tftp://10.0.0.10/mybackup.conf

    Why it's wrong here

    FortiGate does not use a 'copy' command for configuration backups — that syntax is typical of Cisco IOS. The FortiGate's operational commands are under 'execute', so 'copy config tftp://...' would produce an 'Unknown action' error. Additionally, FortiGate backup commands take the filename and server as separate positional arguments, not as a URL with a scheme.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

8 more ways this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator needs to back up the full configuration of a FortiGate, including all system settings, policies, and objects. Which CLI command should be used?

easy
  • A.diagnose debug config-error-log read
  • ✓ B.execute backup config tftp <filename> <server>
  • C.show full-configuration
  • D.execute restore config tftp <filename> <server>

Why B: The correct command is 'execute backup config tftp <filename> <server>' because it explicitly triggers a full configuration backup (including system settings, policies, and objects) to a TFTP server. This is the standard FortiGate CLI command for exporting the entire running configuration to an external TFTP server, ensuring all configuration elements are captured.

Variation 2. An administrator needs to back up the FortiGate configuration to a remote server using SCP. Which command is correct?

easy
  • A.execute backup config copy <server> <filename>
  • ✓ B.execute backup config scp <server> <filename>
  • C.execute backup config tftp <server> <filename>
  • D.execute backup config ftp <server> <filename>

Why B: The correct command is 'execute backup config scp <server> <filename>' because SCP (Secure Copy Protocol) is the only option listed that provides encrypted file transfer over SSH, which is required for securely backing up the FortiGate configuration to a remote server. FortiGate uses this CLI command to initiate an SCP session to the specified server and save the configuration file with the given filename.

Variation 3. An administrator needs to back up the FortiGate configuration to a remote server. Which protocol is supported for backup?

easy
  • A.FTP
  • B.SNMP
  • C.HTTP
  • ✓ D.TFTP

Why D: FortiGate supports backing up its configuration to a remote server using TFTP (Trivial File Transfer Protocol). TFTP is a lightweight, UDP-based protocol (port 69) that is commonly used for network device configuration backups because it requires minimal overhead and is widely supported by TFTP servers. The backup command in FortiGate CLI, such as 'execute backup config tftp <filename> <server-ip>', specifically uses TFTP for this purpose.

Variation 4. An administrator wants to back up the FortiGate configuration to a remote FTP server. Which command should be used?

medium
  • A.execute restore config ftp <filename> <server>
  • B.copy running-config startup-config
  • C.execute backup system ftp <filename> <server>
  • ✓ D.execute backup config ftp <filename> <server>

Why D: The `execute backup config ftp` command is the specific FortiGate CLI command designed to back up the configuration file to a remote FTP server. This command directly initiates an FTP transfer of the current system configuration, ensuring the backup is stored externally for disaster recovery.

Variation 5. An administrator wants to back up the FortiGate configuration to a TFTP server at 10.10.10.10. Which CLI command should be used?

medium
  • ✓ A.execute backup config tftp 10.10.10.10
  • B.backup config tftp 10.10.10.10
  • C.copy config tftp 10.10.10.10
  • D.execute save config tftp 10.10.10.10

Why A: The correct command to back up a FortiGate configuration to a TFTP server is 'execute backup config tftp <server-ip>'. This is because 'execute' is the FortiOS CLI keyword for initiating operational commands, and 'backup config tftp' specifies the action and protocol. The syntax is case-sensitive and must include the 'execute' prefix to be recognized by the FortiGate CLI.

Variation 6. A FortiGate administrator wants to ensure that all firewall policies are backed up before performing a firmware upgrade. Which backup method preserves the configuration in a format that can be restored to the same or different FortiGate model?

easy
  • A.Use 'execute backup full-config tftp'
  • B.Copy the configuration from the system config script
  • ✓ C.Backup the configuration via CLI using 'execute backup config tftp'
  • D.Save the running config from the GUI Dashboard

Why C: 'execute backup config tftp' saves the FortiGate configuration in a plain-text, human-readable format that can be restored to the same or a different FortiGate model. This command backs up only the configuration (not firmware or logs) and is model-agnostic, allowing restoration across different hardware platforms as long as the firmware version is compatible.

Variation 7. A FortiGate administrator needs to backup the configuration to a remote TFTP server. Which CLI command should be used?

easy
  • A.copy config tftp <filename> <tftp_server_ip>
  • B.execute restore config tftp <filename> <tftp_server_ip>
  • ✓ C.execute backup config tftp <filename> <tftp_server_ip>
  • D.backup configuration to tftp <tftp_server_ip>

Why C: The 'execute backup config tftp' command is the proper CLI syntax in FortiOS for backing up the current configuration to a remote TFTP server. This command triggers an immediate backup operation, and the filename and TFTP server IP are required parameters to specify the destination.

Variation 8. A FortiGate administrator needs to configure a backup and restore strategy for the FortiGate configuration. Which TWO statements are correct regarding configuration backup and restore?

medium
  • ✓ A.When restoring a configuration to a different FortiGate model, the interface names may cause the restore to fail.
  • B.The encrypted backup can only be restored on a FortiGate running the same firmware version.
  • C.It is not possible to restore only a specific section of the configuration (e.g., only firewall policies).
  • D.The backup file is encrypted by default to protect sensitive information.
  • ✓ E.The backup file contains all system settings, including firmware version information.

Why A: Option A is correct because interface names are model-specific (for example, internal, wan1, port1), so restoring a configuration from one FortiGate model to a different model can fail or misconfigure interfaces when the target lacks matching interface names. Option E is correct because the configuration backup file includes the full system settings and records the firmware version, which is why FortiGate can warn about version mismatches during restore. Option B is incorrect because an encrypted backup is not strictly limited to the exact same firmware version; it can be restored on compatible firmware, and the encryption is tied to the password, not solely the firmware build. Option C is incorrect because FortiGate supports restoring specific configuration sections or using partial restore/script methods rather than only a full restore. Option D is incorrect because backups are not encrypted by default; the administrator must enable password-based encryption when creating the backup.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.