nerdexam
Fortinet

NSE4 · Question #510

When an administrator attempts to manage FortiGate from an IP address that is not a trusted host, what happens?

The correct answer is B. FortiGate will drop the packets and not respond.. If an administrator attempts to manage a FortiGate from an IP address not configured as a trusted host, the device will silently drop the connection.

Submitted by khalil_dz· Apr 18, 2026FortiGate Deployment and System Configuration

Question

When an administrator attempts to manage FortiGate from an IP address that is not a trusted host, what happens?

Options

  • AFortiGate will still subject that person's traffic to firewall policies; it will not bypass them.
  • BFortiGate will drop the packets and not respond.
  • CFortiGate responds with a block message, indicating that it will not allow that person to log in.
  • DFortiGate responds only if the administrator uses a secure protocol. Otherwise, it does not

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    86% (19)
  • D
    9% (2)

Why each option

If an administrator attempts to manage a FortiGate from an IP address not configured as a trusted host, the device will silently drop the connection.

AFortiGate will still subject that person's traffic to firewall policies; it will not bypass them.

The trusted host setting specifically controls management access and takes precedence over regular firewall policies for management connections, so it does not subject these attempts to general policies.

BFortiGate will drop the packets and not respond.Correct

The trusted host feature acts as an implicit security rule; FortiGate will drop packets originating from untrusted management IPs without sending any response, making the device appear unresponsive to unauthorized access attempts.

CFortiGate responds with a block message, indicating that it will not allow that person to log in.

FortiGate does not respond with a block message; instead, it drops the packets silently as a security measure to avoid indicating its presence or configuration to an unauthorized party.

DFortiGate responds only if the administrator uses a secure protocol. Otherwise, it does not

The trusted host configuration applies regardless of the protocol's security; if the source IP is untrusted, management access is blocked, whether secure (HTTPS) or insecure (HTTP).

Concept tested: FortiGate trusted host management security

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/184232/trusted-hosts

Topics

#Administrative Access#Trusted Hosts#Security Features#FortiGate Management

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice