NSE4 System and Network Administration Practice Question
A FortiGate administrator needs to configure a static route to reach a remote network 192.168.100.0/24 via next-hop 10.0.0.1. Which CLI command should be used?
⚠ Common exam trap
The trap here is that candidates familiar with Cisco IOS may use 'set destination' or 'set next-hop' (similar to Cisco's 'ip route' command) or CIDR notation, but FortiGate requires 'set dst' with a subnet mask and 'set gateway' for the next-hop, testing knowledge of vendor-specific CLI syntax.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
config router static edit 1 set dst 192.168.100.0 255.255.255.0 set gateway 10.0.0.1 next end
It uses the proper FortiGate CLI syntax for configuring a static route. The command 'config router static' enters the static route configuration context, and 'set dst' specifies the destination network with a subnet mask (not CIDR notation), while 'set gateway' defines the next-hop IP address. This matches the FortiGate CLI structure for static routes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
config network route edit 1 set ip 192.168.100.0 255.255.255.0 set gateway 10.0.0.1 end
Why it's wrong here
This fails because FortiOS does not implement a configuration mode named 'config network route'; static routes live exclusively under 'config router static'. The command would be rejected by the CLI parser before any settings are read. Moreover, 'set ip' is not a valid keyword for a route entry—FortiOS uses 'set dst' to define the destination network.
- ✓
config router static edit 1 set dst 192.168.100.0 255.255.255.0 set gateway 10.0.0.1 next end
Why this is correct
This is the exact FortiOS syntax for a static route. 'config router static' enters the static routing table, 'edit 1' creates or edits the route with sequence number 1, and 'set dst' accepts the destination address followed by subnet mask. 'set gateway' defines the next-hop IP, then 'next' commits the entry and 'end' exits configuration mode. This block is valid and works as intended.
- ✗
config route static edit 1 set destination 192.168.100.0/24 set next-hop 10.0.0.1 end
Why it's wrong here
Two fatal problems exist here: the container is backwards—'config route static' is not a recognized branch; the correct tree is 'config router static'. In addition, FortiGate route entries never use 'set destination' or 'set next-hop'; those are generic network terms, not FortiOS CLI keywords. The proper parameters are 'set dst' for the destination prefix and 'set gateway' for the next hop, so this snippet cannot configure anything.
- ✗
config router static edit 1 set dst 192.168.100.0/24 set next-hop 10.0.0.1 end
Why it's wrong here
This command gets the container right ('config router static') but still fails because FortiOS does not accept CIDR notation in 'set dst'—it requires the network address and netmask as separate arguments, for example 'set dst 192.168.100.0 255.255.255.0'. Additionally, 'set next-hop' is not a valid FortiOS route command; the gateway is defined only with 'set gateway'. Even if the prefix were entered correctly, the wrong keyword name would cause an error.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.