Courseiva

NSE4 System and Network Administration Practice Question

A FortiGate administrator is setting up a new FortiGate in a network that requires the firewall to bridge traffic between two subnets without routing. Which operating mode should the administrator select?

⚠ Common exam trap

Many exam-takers confuse transparent mode with VLAN mode, thinking VLANs are a separate operating mode, or they assume NAT/Route mode can bridge traffic by disabling NAT, but it still performs routing at Layer 3.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Transparent mode

Transparent mode allows the FortiGate to act as a Layer 2 bridge, forwarding traffic between two subnets without performing any routing or NAT. In this mode, the firewall operates like a 'bump in the wire,' inspecting and filtering traffic based on MAC addresses and Layer 2 headers, while the IP addresses of connected devices remain unchanged. This is ideal for scenarios where the FortiGate must be inserted into an existing network without altering the IP topology.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Transparent mode

    Why this is correct

    In Transparent mode, the FortiGate operates as a Layer 2 bridge, forwarding Ethernet frames between interfaces based on MAC addresses, much like a wire or switch. It performs no routing or NAT, so existing IP addressing and subnetting remain unchanged, and the device is effectively invisible to the network. This is the correct answer because transparent mode is specifically designed for inline deployment without modifying the Layer 3 topology.

  • ✗

    NAT/Route mode

    Why it's wrong here

    NAT/Route mode makes the FortiGate a Layer 3 router: it forwards packets based on IP routing tables, requires different IP subnets on each interface, and typically applies NAT boundary functions. It does not bridge traffic at Layer 2, so it cannot provide transparent insertion into an existing segment. Because the question calls for a transparent bridging capability, NAT/Route mode is incorrect for that reason.

  • ✗

    HA mode

    Why it's wrong here

    HA mode is a high-availability feature that pairs two FortiGates into a cluster for redundancy and failover, either active-passive or active-active. It is not an operating mode for packet forwarding; rather, it is a deployment scenario that can run on top of either Transparent or NAT/Route mode. Therefore, HA mode cannot be selected as the bridging operating mode because it does not define how traffic is bridged or routed.

  • ✗

    VLAN mode

    Why it's wrong here

    FortiOS does not include a separate 'VLAN mode'; VLANs are configured as subinterfaces or tagged interfaces within either Transparent or NAT/Route mode. While you can create 802.1Q VLANs to segment traffic, that is a feature, not a standalone operating mode. This option is incorrect because it conflates the ability to handle VLAN tags with a distinct forwarding mode that does not actually exist.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.