NSE4 · Question #249
An administrator logs into a FortiGate unit using an account which has been assigned a super_admin profile. Which of the following operations can this administrator perform?
The correct answer is C. They can delete the admin account if the default admin user is not logged in. An administrator with the super_admin profile possesses the highest level of privileges on a FortiGate unit, enabling them to delete other admin accounts, including the default 'admin' account, provided it is not currently logged in.
Question
An administrator logs into a FortiGate unit using an account which has been assigned a super_admin profile. Which of the following operations can this administrator perform?
Options
- AThey can delete logged-in users who are also assigned the super_admin access profile.
- BThey can make changes to the super_admin profile.
- CThey can delete the admin account if the default admin user is not logged in.
- DThey can view all the system configuration settings but can not make changes.
- EThey can access configuration options for only the VDOMs to which they have been assigned.
How the community answered
(42 responses)- A2% (1)
- C90% (38)
- D5% (2)
- E2% (1)
Why each option
An administrator with the super_admin profile possesses the highest level of privileges on a FortiGate unit, enabling them to delete other admin accounts, including the default 'admin' account, provided it is not currently logged in.
A super_admin cannot delete another super_admin account that is currently logged in, as this prevents interference with active sessions and maintains system stability.
Even a super_admin cannot modify the super_admin *profile* itself, as it is a built-in, unchangeable system profile with fixed maximum permissions.
The super_admin profile grants full read and write access to all configuration options on the FortiGate unit, including the ability to manage other administrator accounts. This includes deleting the default 'admin' account, provided that account is not actively logged in at the time of the operation.
A super_admin profile provides full read and *write* access to all system configuration settings, not just view access.
A super_admin account, by default, has access to all VDOMs (if VDOMs are enabled) without specific assignment limitations, providing overarching control.
Concept tested: FortiGate super_admin profile permissions
Source: https://docs.fortinet.com/document/fortigate/7.0.0/administration-guide/339414/administrator-profiles
Topics
Community Discussion
No community discussion yet for this question.