Courseiva

NSE4 System and Network Administration Practice Question

Which THREE statements about FortiGate's 'config system global' settings are true? (Choose three.)

⚠ Common exam trap

Candidates often confuse global system settings with interface-specific or admin-specific settings, leading candidates to select 'trusthost' or 'allowaccess' which are configured in different contexts (admin and interface respectively).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The 'admin-login-retry-limit' setting limits the number of failed login attempts before lockout.

The 'admin-login-retry-lockout' setting (often referred to as 'admin-login-retry-limit' in older firmware) defines the number of consecutive failed administrative login attempts before the administrator account is locked out for a specified duration. This is a security feature to prevent brute-force attacks against the management interface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The 'trusthost' setting restricts administrative access to specific source IPs.

    Why it's wrong here

    The 'trusthost' parameter is not part of config system global; it is configured under individual administrator accounts (config system admin) to limit which source IP addresses that admin can log in from. While trusthost does restrict administrative access, it is an admin-scoped setting rather than a global device-wide parameter. The exam traps you into thinking it belongs with global security settings, but it lives elsewhere.

  • ✓

    The 'admin-login-retry-limit' setting limits the number of failed login attempts before lockout.

    Why this is correct

    This is correct because 'admin-login-retry-limit' is a global security setting under config system global. It defines the maximum number of consecutive failed administrator login attempts (default is 3) before the source IP is locked out for a period (admin-lockout-duration). This helps mitigate brute-force attacks on management interfaces and applies across all administrators and access methods.

  • ✓

    The 'hostname' setting sets the device name displayed in the GUI.

    Why this is correct

    The 'hostname' setting under config system global defines the device's network identity, displayed in the GUI, CLI prompt, and as the SNMP sysName. It is device-wide and not tied to any specific admin or interface. Changing it requires a system administrator and takes effect immediately without rebooting.

  • ✗

    The 'allowaccess' setting controls which protocols are allowed on an interface.

    Why it's wrong here

    The 'allowaccess' setting is configured under config system interface, not under config system global, and it specifies which management protocols (such as HTTPS, HTTP, SSH, PING) are allowed on that specific interface. It determines how administrators can reach the FortiGate for management through that interface, not global traffic forwarding. Because it is interface-scoped, different interfaces can have different allowaccess lists.

  • ✓

    The 'timezone' setting sets the FortiGate's local time zone.

    Why this is correct

    The 'timezone' setting under config system global sets the device's local time zone, which determines the timestamps used in logs, reports, and scheduled tasks. It supports IANA timezone names, such as 'America/New_York', and is critical for accurate auditing across multi-site deployments. This global setting affects all administrators and log entries uniformly.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.