NSE4 System and Network Administration Practice Question
Which command is used to back up the full FortiGate configuration including all settings and objects?
⚠ Common exam trap
Many candidates confuse the correct command with similar-sounding but invalid options like 'execute backup full-config' or 'config backup tftp', or assume a 'system' subcommand exists for backups, when FortiGate uses the 'execute' command structure for operational tasks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
execute backup config
The 'execute backup config' command is the correct method to back up the full FortiGate configuration, including all settings and objects, to a TFTP or FTP server. This command exports the entire running configuration in a text format that can be restored later. It is the standard CLI command for a complete configuration backup.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
execute backup config
Why this is correct
execute backup config is the correct FortiGate CLI command to back up the full configuration. It captures all system, network, and firewall policy settings into a single plain-text file. This command can be run interactively to save to local disk or with parameters like tftp, ftp, or scp for remote transfer. It is the standard, intended method for creating a complete configuration backup.
- ✗
execute backup full-config
Why it's wrong here
execute backup full-config is not a valid FortiGate CLI command; the correct syntax is 'execute backup config'. The term 'full-config' is not a recognized argument in the execute backup command, so the CLI will reject it with an error. To archive the entire configuration, you must use the exact command 'execute backup config' without additional descriptors such as 'full'. This ensures the backup process is recognized and executed correctly.
- ✗
config backup tftp
Why it's wrong here
config backup tftp is not a valid command because it incorrectly places 'backup' as a subcommand of the 'config' mode. On FortiGate, 'config' is used to enter configuration modes (e.g., config system or config firewall), while backups are invoked from the 'execute' mode. The proper syntax for a TFTP backup is 'execute backup config tftp <filename> <server>'. Attempting 'config backup tftp' will return an unknown command error since the CLI does not support that structure.
- ✗
system backup configuration
Why it's wrong here
system backup configuration is not recognized by the FortiGate CLI because there is no 'system' command that initiates a backup. Backups are performed exclusively via the 'execute' command group, not through a 'system' submenu. Additionally, 'configuration' is not a valid parameter; the correct argument is 'config'. On FortiGate, the exact command is 'execute backup config', and any deviation from this syntax will fail to execute.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which command is used to back up the FortiGate configuration to a TFTP server?
easy- A.save config tftp <filename> <server_ip>
- B.backup tftp config <filename> <server_ip>
- ✓ C.execute backup config tftp <filename> <server_ip>
- D.copy config tftp <filename> <server_ip>
Why C: The correct command to back up the FortiGate configuration to a TFTP server is 'execute backup config tftp <filename> <server_ip>'. This is because FortiGate uses the 'execute' command for operational tasks, and 'backup config tftp' specifically instructs the system to export the running configuration to a TFTP server. The other options use incorrect syntax or commands that are not recognized by the FortiGate CLI.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.