Courseiva

NSE4 · topic practice

System and Network Administration practice questions

This domain covers FortiGate system and network administration: interface and route configuration, policy routes, WAN link load balancing, transparent mode, firmware upgrades, and administrative access. Questions present a symptom (traffic ignoring PBR, unwanted load balancing) or a configuration scenario and ask which setting, mode, or step resolves it correctly.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: System and Network Administration

What the exam tests

What to know about System and Network Administration

Be able to configure and verify policy routes, WAN link load balancing, transparent mode, and firmware upgrades on a FortiGate. The single most important thing: confirm a policy route actually matches the traffic by checking sequence, source, destination, and incoming interface before blaming the default route.

Configuring policy routes (PBR) with correct sequence, gateway, and incoming interface matching

Using SD-WAN or WAN LLB to control per-destination link selection

Applying FortiGate transparent mode behavior, including no IP on data interfaces

Planning firmware upgrade path and configuration backup before version changes

Watch out for

Common System and Network Administration exam traps

  • ▸Assuming PBR overrides everything: policy routes are evaluated before the routing table, but wrong sequence, source, or incoming interface makes them never match.
  • ▸Confusing WAN LLB with SD-WAN: LLB load-balances by destination, so a specific subnet may still spread across links unless excluded.
  • ▸Upgrading firmware without checking the supported upgrade path or taking a config backup, risking failed boot or lost settings.

Practice set

System and Network Administration questions

20 questions · select your answer, then reveal the explanation

Which ONE of the following is a valid method to upgrade the FortiGate firmware? (Choose one.)

An administrator needs to configure a FortiGate to send logs to two different syslog servers for redundancy. Which configuration method should be used?

Refer to the exhibit. The administrator notices that traffic from internal to wan1 is being logged, but the logs do not show the original source IP. What is the most likely reason?

Exhibit

config firewall policy
    edit 1
        set srcintf "internal"
        set dstintf "wan1"
        set srcaddr "all"
        set dstaddr "all"
        set action accept
        set schedule "always"
        set service "ALL"
        set logtraffic all
        set nat enable
    next
end
Question 4mediummultiple choice
Study the full SD-WAN breakdown →

A company has a FortiGate 200F with FortiOS 7.2 and two ISPs (WAN1: 100 Mbps, WAN2: 50 Mbps). The company uses SD-WAN to load balance outbound internet traffic. Recently, the company added a new VoIP application that requires low latency and jitter. The administrator configured an SD-WAN rule to match the VoIP traffic and set the strategy to 'best quality' with a performance SLA measuring latency and jitter. However, after testing, the VoIP traffic is still using WAN2 (the slower link) even when WAN1 has lower latency. The performance SLA shows both links meeting the SLA thresholds. What is the most likely reason?

A company is deploying a FortiGate HA cluster in active-passive mode across two data centers. The network team reports that after a failover, some existing TCP sessions are dropped. Which configuration change should be applied to maintain session persistence during failover?

Which THREE configuration steps are required to enable transparent proxy mode on a FortiGate?

Match each FortiGate security profile component to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Scans files for malware

Controls access to URLs and web categories

Identifies and allows/denies application traffic

Detects and blocks network attacks

Decrypts encrypted traffic for inspection

Question 8mediummultiple choice
Review the full routing breakdown →

An administrator runs 'diagnose sniffer packet any "host 10.0.1.100" 4' and sees packets being sent but no response. The FortiGate has a static route for 10.0.1.0/24 via 192.168.1.1. The administrator checks the routing table and sees the route is present. What is the most likely cause of no response?

A FortiGate is configured in transparent mode. The administrator notices that traffic passing through the FortiGate is not being logged, even though log all sessions is enabled on the policy. What is the most likely reason?

Question 10mediummultiple choice
Read the full network assurance explanation →

An administrator configures SNMP on a FortiGate to monitor CPU and memory usage. After applying the configuration, the NMS cannot reach the FortiGate via SNMP. The FortiGate's interface has SNMP access enabled. What is the most likely missing configuration?

An administrator needs to integrate a FortiGate with FortiAnalyzer for centralized logging. After configuring the FortiAnalyzer IP and enabling logging, the FortiGate shows 'connection refused' for FortiAnalyzer. What is the most likely cause?

An administrator is configuring a FortiGate HA cluster in active-passive mode. Which two statements are correct about this configuration?

Question 13hardmulti select
Read the full VPN explanation →

A FortiGate administrator is troubleshooting a VPN tunnel that is not coming up. The phase 1 parameters match on both sides. Which three configuration items should the administrator verify?

An administrator is configuring a FortiGate to use FortiManager for centralized management. Which three steps are required?

Which of the following is required to allow a FortiGate to synchronize its clock with an NTP server?

You run the following CLI command on a FortiGate: 'diagnose sys session filter dport 443' and see this output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate?

A FortiGate administrator needs to configure NTP to ensure accurate time on the device. Which two steps are required? (Choose two.)

Question 18hardmulti select
Open the full VLAN trunking answer →

An administrator is configuring a FortiGate in transparent mode and needs to forward traffic between two VLANs. Which three configurations are required? (Choose three.)

An admin configures an aggregate interface on a FortiGate using two physical ports. After configuration, the admin notices that traffic is not load-balancing evenly. What is the MOST likely cause?

During a firmware upgrade, the admin uploads the image via the GUI and clicks 'Upgrade'. The FortiGate reboots but comes up with the old firmware. What is the MOST likely cause?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused System and Network Administration sessions

Start a System and Network Administration only practice session

Every question in these sessions is drawn from the System and Network Administration domain — nothing else.

Related practice questions

Related NSE4 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the NSE4 exam test about System and Network Administration?
Be able to configure and verify policy routes, WAN link load balancing, transparent mode, and firmware upgrades on a FortiGate. The single most important thing: confirm a policy route actually matches the traffic by checking sequence, source, destination, and incoming interface before blaming the default route.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just System and Network Administration questions in a focused session?
Yes — the session launcher on this page draws every question from the System and Network Administration domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other NSE4 topics?
Use the topic links above to move to related areas, or go back to the NSE4 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the NSE4 exam covers. They are not copied from any real exam or dump site.