NSE4 System and Network Administration Practice Question
A FortiGate admin needs to create a loopback interface for management purposes. Which two statements about loopback interfaces are correct? (Choose two.)
⚠ Common exam trap
Candidates often assume loopback interfaces are only for routing protocols or that they cannot have an IP address, but FortiGate loopback interfaces fully support IP addressing and are used for multiple purposes including management and VPN termination.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Loopback interfaces are always up and do not depend on physical links
Loopback interfaces are virtual interfaces that are always in an up/up state as long as the FortiGate is operational. They do not depend on any physical link or carrier status, making them ideal for management access and stable routing protocol peering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Loopback interfaces are always up and do not depend on physical links
Why this is correct
A loopback interface in FortiOS is a virtual interface that has no physical hardware dependency; its operational status is tied to the system's presence and never to any link state. Consequently, the loopback stays up unless the FortiGate itself is rebooted or powered off, even if every physical port is down. This makes it the preferred logical anchor for router IDs, management sessions, and services that need uninterrupted reachability.
- ✓
Loopback interfaces can be used to terminate IPSec VPN tunnels
Why this is correct
On FortiGate, a loopback interface can be designated as the local address for an IPsec tunnel, which is especially useful in hub-and-spoke and dynamic encrypted topologies. Because the loopback is not bound to any specific physical interface or link state, the tunnel remains stable when a WAN interface fails or ISPs swap. This allows the IPsec negotiation to always use the same source IP across the FortiGate's entire lifecycle and can simplify routing and failover.
- ✗
Loopback interfaces cannot be assigned an IP address
Why it's wrong here
This is false: FortiOS loopback interfaces are fully configurable with an IP address and netmask, just like any physical interface. You can assign an IPv4 or IPv6 address, optionally secondary addresses, and the loopback will respond to ping or serve as a management address. Without an IP, the interface would be of little use for most network functions, so FortiOS explicitly supports common address assignment.
- ✗
Loopback interfaces are only used for routing protocols
Why it's wrong here
Loopback interfaces are often used for OSPF or BGP router IDs, but that is not their only purpose. They also function as stable management-access addresses, source interfaces for Syslog/SNMP/NetFlow, endpoints for IPsec tunnels, and targets for policy-based NAT or health checks. Calling them exclusive to routing protocols ignores the many tasks where a permanent, non-physical interface is beneficial.
- ✗
Loopback interfaces require a physical port to be up
Why it's wrong here
A loopback interface is purely software-defined and has no association with any physical port, so it does not require a physical link to be up. It remains administratively and operationally up as long as the FortiGate is running, even when all physical interfaces are disconnected or down. This independence is the entire reason it provides high availability for management and routing protocols.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.