NSE4 · Question #145
When creating administrative users which of the following configuration objects determines access rights on the FortiGate unit.
The correct answer is A. profile. When creating administrative users on a FortiGate unit, the assigned admin profile determines the specific access rights and permissions the user has to different configuration areas.
Question
When creating administrative users which of the following configuration objects determines access rights on the FortiGate unit.
Options
- Aprofile
- Ballowaccess interface settings
- Coperation mode
- Dlocal-in policy
How the community answered
(55 responses)- A89% (49)
- B2% (1)
- C4% (2)
- D5% (3)
Why each option
When creating administrative users on a FortiGate unit, the assigned admin `profile` determines the specific access rights and permissions the user has to different configuration areas.
An administrative profile explicitly defines the permissions and access rights of a user to specific areas of the FortiGate configuration and monitoring, controlling what they can view and modify.
`allowaccess` interface settings determine which management protocols (e.g., HTTPS, SSH) are allowed on a specific interface, not the granular access rights of an administrative user.
Operation mode (e.g., NAT/Route, Transparent) defines how the FortiGate functions within the network, but it does not directly control individual administrative user access rights.
A local-in policy is a firewall policy that controls traffic destined for the FortiGate itself, protecting management interfaces, but it does not define the internal access permissions of an authenticated administrator.
Concept tested: FortiGate admin profiles
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/760431/creating-administrative-profiles
Topics
Community Discussion
No community discussion yet for this question.