NSE4 · Question #73
When creating FortiGate administrative users, which configuration objects specify the account rights?
The correct answer is C. Administrator profiles. When creating administrative users on a FortiGate, administrator profiles are the configuration objects used to define their specific permissions and access rights.
Question
When creating FortiGate administrative users, which configuration objects specify the account rights?
Options
- ARemote access profiles.
- BUser groups.
- CAdministrator profiles.
- DLocal-in policies.
How the community answered
(17 responses)- A6% (1)
- B6% (1)
- C88% (15)
Why each option
When creating administrative users on a FortiGate, administrator profiles are the configuration objects used to define their specific permissions and access rights.
Remote access profiles are typically used for VPN users and define authentication and authorization for remote access, not the rights of administrative users.
User groups are used to categorize end-users for firewall policies, authentication, and VPN access, not to define administrative access rights.
Administrator profiles allow for granular control over what an administrator can view, configure, and execute on the FortiGate, dictating their access rights to different parts of the configuration and monitoring features. Each administrative user is assigned one of these profiles to define their privileges.
Local-in policies control traffic destined for the FortiGate itself (like management access), but they do not define the specific administrative rights of a user once authenticated.
Concept tested: FortiGate administrative user profiles
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/567634/administrator-profiles
Topics
Community Discussion
No community discussion yet for this question.