NSE4 System and Network Administration Practice Question
A FortiGate administrator is configuring a new VLAN interface on a managed FortiSwitch. The FortiGate is the FortiLink parent. The administrator wants to ensure that the VLAN is properly recognized and that traffic can flow between the FortiGate and devices on that VLAN. Which two actions must the administrator perform? (Choose two.)
⚠ Common exam trap
The trap here is assuming that creating the VLAN on the FortiGate alone is sufficient, without also configuring the VLAN on the FortiSwitch ports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the VLAN on the FortiSwitch using the FortiGate GUI or CLI, assigning it to the desired ports.
For a VLAN to function on a FortiLink-managed FortiSwitch, the FortiGate must have a VLAN interface with the matching VLAN ID bound to the FortiLink interface, and the FortiSwitch must have the VLAN configured on the appropriate ports. These two steps ensure the VLAN is recognized and traffic can flow. Other options are either optional security features or unnecessary configuration steps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the VLAN on the FortiSwitch using the FortiGate GUI or CLI, assigning it to the desired ports.
Why this is correct
The FortiSwitch must have the VLAN defined and assigned to the ports where devices will connect. This is typically done via the FortiGate's managed switch configuration, which pushes the VLAN settings to the FortiSwitch. Without this, the VLAN is not present on the switch ports.
- ✓
Create a VLAN interface on the FortiGate with the same VLAN ID and assign it to the FortiLink interface.
Why this is correct
To allow traffic on a VLAN, the FortiGate must have a VLAN interface configured with the matching VLAN ID, and it must be associated with the FortiLink interface. This enables the FortiGate to tag and untag traffic appropriately on the FortiLink trunk.
- ✗
Enable DHCP snooping on the FortiGate for the VLAN to prevent rogue DHCP servers.
Why it's wrong here
DHCP snooping is a security feature that can be enabled on the FortiSwitch, but it is not required for basic VLAN traffic flow. The question asks for actions to ensure the VLAN is recognized and traffic can flow, not for security hardening. This action is optional and not a prerequisite.
- ✗
Set the FortiLink interface to dedicated mode to allow VLAN tagging.
Why it's wrong here
FortiLink can operate in dedicated or aggregate mode, but changing to dedicated mode is not required for VLAN tagging. VLAN tagging works in both modes. Dedicated mode uses a single interface, but it does not enable VLAN functionality by itself. This action is not necessary.
- ✗
Configure a static route on the FortiGate for the VLAN subnet pointing to the FortiLink interface.
Why it's wrong here
A static route is not needed for directly connected VLAN subnets; the FortiGate automatically adds a connected route when the VLAN interface is created. Adding a static route would be redundant and could cause confusion. This action is not required for basic VLAN operation.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.