nerdexam
Fortinet

NSE4 · Question #249

An administrator logs into a FortiGate unit using an account which has been assigned a super_admin profile. Which of the following operations can this administrator perform?

The correct answer is C. They can delete the admin account if the default admin user is not logged in. An administrator with the super_admin profile possesses the highest level of privileges on a FortiGate unit, enabling them to delete other admin accounts, including the default 'admin' account, provided it is not currently logged in.

Submitted by omar99· Apr 18, 2026FortiGate Deployment and System Configuration

Question

An administrator logs into a FortiGate unit using an account which has been assigned a super_admin profile. Which of the following operations can this administrator perform?

Options

  • AThey can delete logged-in users who are also assigned the super_admin access profile.
  • BThey can make changes to the super_admin profile.
  • CThey can delete the admin account if the default admin user is not logged in.
  • DThey can view all the system configuration settings but can not make changes.
  • EThey can access configuration options for only the VDOMs to which they have been assigned.

How the community answered

(42 responses)
  • A
    2% (1)
  • C
    90% (38)
  • D
    5% (2)
  • E
    2% (1)

Why each option

An administrator with the super_admin profile possesses the highest level of privileges on a FortiGate unit, enabling them to delete other admin accounts, including the default 'admin' account, provided it is not currently logged in.

AThey can delete logged-in users who are also assigned the super_admin access profile.

A super_admin cannot delete another super_admin account that is currently logged in, as this prevents interference with active sessions and maintains system stability.

BThey can make changes to the super_admin profile.

Even a super_admin cannot modify the super_admin *profile* itself, as it is a built-in, unchangeable system profile with fixed maximum permissions.

CThey can delete the admin account if the default admin user is not logged in.Correct

The super_admin profile grants full read and write access to all configuration options on the FortiGate unit, including the ability to manage other administrator accounts. This includes deleting the default 'admin' account, provided that account is not actively logged in at the time of the operation.

DThey can view all the system configuration settings but can not make changes.

A super_admin profile provides full read and *write* access to all system configuration settings, not just view access.

EThey can access configuration options for only the VDOMs to which they have been assigned.

A super_admin account, by default, has access to all VDOMs (if VDOMs are enabled) without specific assignment limitations, providing overarching control.

Concept tested: FortiGate super_admin profile permissions

Source: https://docs.fortinet.com/document/fortigate/7.0.0/administration-guide/339414/administrator-profiles

Topics

#Administrator Profiles#User Management#Access Control#FortiGate Administration

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice