NSE4 System and Network Administration Practice Question
A FortiGate administrator is setting up a new FortiGate in a network that requires the firewall to bridge traffic between two subnets without routing. Which operating mode should the administrator select?
⚠ Common exam trap
Many exam-takers confuse transparent mode with VLAN mode, thinking VLANs are a separate operating mode, or they assume NAT/Route mode can bridge traffic by disabling NAT, but it still performs routing at Layer 3.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Transparent mode
Transparent mode allows the FortiGate to act as a Layer 2 bridge, forwarding traffic between two subnets without performing any routing or NAT. In this mode, the firewall operates like a 'bump in the wire,' inspecting and filtering traffic based on MAC addresses and Layer 2 headers, while the IP addresses of connected devices remain unchanged. This is ideal for scenarios where the FortiGate must be inserted into an existing network without altering the IP topology.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Transparent mode
Why this is correct
In Transparent mode, the FortiGate operates as a Layer 2 bridge, forwarding Ethernet frames between interfaces based on MAC addresses, much like a wire or switch. It performs no routing or NAT, so existing IP addressing and subnetting remain unchanged, and the device is effectively invisible to the network. This is the correct answer because transparent mode is specifically designed for inline deployment without modifying the Layer 3 topology.
- ✗
NAT/Route mode
Why it's wrong here
NAT/Route mode makes the FortiGate a Layer 3 router: it forwards packets based on IP routing tables, requires different IP subnets on each interface, and typically applies NAT boundary functions. It does not bridge traffic at Layer 2, so it cannot provide transparent insertion into an existing segment. Because the question calls for a transparent bridging capability, NAT/Route mode is incorrect for that reason.
- ✗
HA mode
Why it's wrong here
HA mode is a high-availability feature that pairs two FortiGates into a cluster for redundancy and failover, either active-passive or active-active. It is not an operating mode for packet forwarding; rather, it is a deployment scenario that can run on top of either Transparent or NAT/Route mode. Therefore, HA mode cannot be selected as the bridging operating mode because it does not define how traffic is bridged or routed.
- ✗
VLAN mode
Why it's wrong here
FortiOS does not include a separate 'VLAN mode'; VLANs are configured as subinterfaces or tagged interfaces within either Transparent or NAT/Route mode. While you can create 802.1Q VLANs to segment traffic, that is a feature, not a standalone operating mode. This option is incorrect because it conflates the ability to handle VLAN tags with a distinct forwarding mode that does not actually exist.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.