Courseiva

NSE4 System and Network Administration Practice Question

An administrator wants to use FortiManager to manage multiple FortiGates. Which three steps must be performed to establish communication between a FortiGate and FortiManager? (Choose THREE.)

⚠ Common exam trap

Many exam-takers confuse general FortiGate interface configuration (Option C) with the specific FortiManager registration steps, or incorrectly assume transparent mode (Option A) is required for management, when in fact the three required steps are ensuring connectivity, enabling registration with a password, and setting the FortiManager IP address on the FortiGate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure network connectivity between the FortiGate and FortiManager

FortiManager communicates with managed FortiGates over TCP/541 (FGFM protocol). Without IP-level connectivity between the two devices, the registration and management tunnel cannot be established. This is a prerequisite before any configuration steps can succeed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Place the FortiGate in transparent mode

    Why it's wrong here

    Placing the FortiGate in transparent mode is not a prerequisite for FortiManager registration. FortiManager can manage FortiGates in both NAT/route mode and transparent mode, because the management tunnel (TCP 541) operates independently of the data-plane forwarding mode. Transparent mode is only relevant when you want the FortiGate to act as a Layer 2 bridge, but it does not affect the device's ability to reach FortiManager, so this step is unnecessary and will not help complete registration.

  • ✓

    Ensure network connectivity between the FortiGate and FortiManager

    Why this is correct

    Network connectivity between the FortiGate and FortiManager is the fundamental prerequisite for registration. The FortiGate must be able to reach the FortiManager's IP address over TCP port 541, and any intermediate firewalls must permit this traffic, or the registration handshake will time out or be rejected. Without end-to-end IP reachability and correct routing, even the most accurate configuration of other registration parameters will fail, making this the first and most critical requirement.

  • ✗

    Configure the FortiGate's management interface with an IP address

    Why it's wrong here

    Configuring the FortiGate's management interface with an IP address is a general network-setup task, not a specific step for FortiManager registration. In a typical deployment, the FortiGate already has a valid IP address on one of its interfaces, and FortiManager can manage the device through any interface that is reachable from the FortiManager, not necessarily a dedicated management port. Assigning an IP address does not tell the FortiGate where FortiManager is or how to authenticate, so it has no direct bearing on the registration process.

  • ✓

    Enable FortiManager registration and provide a registration password

    Why this is correct

    Enabling FortiManager registration and supplying a registration password is an authentication requirement that secures the initial handshake. When you enable System > FortiManager on the FortiGate, you must configure a registration password that matches the value set on the FortiManager during device provisioning; this password is used to verify that the FortiGate is authorized to join the managed environment. Without a matching password, FortiManager will reject the registration, regardless of reachability or IP configuration, so this step ensures the connection is truly authenticated.

  • ✓

    Set the FortiManager IP address on the FortiGate under System > FortiManager

    Why this is correct

    Setting the FortiManager IP address on the FortiGate under System > FortiManager is the essential configuration that directs the device to the management server. The FortiGate needs this address to know where to send its registration request and to establish the persistent management tunnel; without it, the FortiGate cannot locate FortiManager and registration cannot initiate. This step is specific to FortiManager and clearly identifies the target manager, unlike generic network settings such as IP addresses or operating modes.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.