Courseiva

NSE4 System and Network Administration Practice Question

Exhibit

config system interface
    edit "wan1"
        set vdom "root"
        set ip 10.0.0.1 255.255.255.0
        set allowaccess ping https ssh
        set type wan
        set role wan
        set snmp-index 1
    next
end

Refer to the exhibit. An administrator wants to enable SNMP access on the wan1 interface. Which of the following is the most efficient method?

⚠ Common exam trap

A common mix-up: candidates confuse configuring an SNMP community (which defines who can query) with enabling SNMP access on an interface (which allows the SNMP agent to listen on that interface); both are required, but the question asks for the most efficient method to enable SNMP access on wan1, which is setting 'allowaccess snmp' on that interface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Execute 'config system interface' and edit wan1, then set allowaccess ping https ssh snmp.

The 'allowaccess' parameter under 'config system interface' controls which management protocols (ping, https, ssh, snmp, etc.) are permitted on a given interface. By adding 'snmp' to the allowaccess list for wan1, the administrator enables SNMP access on that interface without changing its role or type.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Execute 'config system interface' and edit wan1, then set allowaccess ping https ssh snmp.

    Why this is correct

    The FortiGate CLI command 'config system interface' followed by 'edit wan1' and 'set allowaccess ping https ssh snmp' explicitly appends snmp to the interface's list of permitted management access services. This is the mandatory per-interface gate: even after defining an SNMP community globally, the FortiGate will only respond to SNMP requests on interfaces whose allowaccess includes snmp. Adding snmp to wan1 therefore enables SNMP agents to serve queries and traps on that interface while preserving existing ping, https, and ssh management access.

  • ✗

    Change the interface type to 'management' to allow SNMP.

    Why it's wrong here

    The interface type in FortiGate is a structural classification (e.g., physical, vlan, loopback, tunnel) and does not act as an access-control switch for SNMP or other management protocols. There is no supported 'management' interface type; even a dedicated management interface still uses the same allowaccess setting to control which services it accepts. Changing the interface type would not add snmp to the allowaccess list, so SNMP requests would remain unanswered on that interface.

  • ✗

    Execute 'config system interface' and edit wan1, then set snmp-index 1.

    Why it's wrong here

    The snmp-index parameter under 'config system interface' defines an arbitrary integer used as the ifIndex in SNMP MIB walks, ensuring a stable identifier for that interface regardless of its order in the system. It is an identification attribute, not an authorization attribute, and it has no bearing on whether SNMP is reachable. Moreover, a snmp-index is typically generated automatically for each interface, so manually setting it adds no functional value for enabling SNMP service.

  • ✗

    Configure an SNMP community under 'config system snmp community'.

    Why it's wrong here

    Creating an SNMP community under 'config system snmp community' defines the authentication credentials, read/write permissions, and allowed manager IPs for SNMPv1/v2c queries, which is a necessary prerequisite for any SNMP communication. However, it is not sufficient: the FortiGate also requires each interface to explicitly include snmp in its allowaccess statement before it will respond on that interface. Without that per-interface permission, the community is configured but silently ignored for wan1 traffic, so SNMP requests will time out.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.