NSE4 System and Network Administration Practice Question
A FortiGate administrator needs to configure a VLAN interface and an aggregate interface. Which THREE statements are correct regarding these interface types?
⚠ Common exam trap
A common mix-up: candidates confuse the mode restrictions for VLANs and aggregates, incorrectly assuming VLANs cannot be used in Transparent mode or that aggregates are limited to NAT/Route mode, when in fact both interface types have broader support.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Aggregate interfaces require at least one physical member to be up.
An aggregate interface (LAG) requires at least one physical member port to be administratively and operationally up for the aggregate itself to be considered up. If all member ports are down, the aggregate interface goes down, which is a fundamental behavior of link aggregation groups (LAGs) per IEEE 802.3ad.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Aggregate interfaces require at least one physical member to be up.
Why this is correct
For an aggregate interface to pass traffic, FortiOS requires at least one physical member interface to be administratively enabled and have a live link; if every member is down, the aggregate port is marked down. This is the basis of the correct answer because it accurately reflects a physical requirement for aggregate interfaces in FortiOS.
- ✗
Aggregate interfaces are only supported in NAT/Route mode.
Why it's wrong here
Link aggregation is a physical-layer redundancy technique available in both NAT/Route and Transparent modes on FortiGate. In Transparent mode, aggregate interfaces can be used to carry 802.1Q VLAN trunks just like any physical interface, and there is no operating-mode restriction on 802.3ad or static aggregate interfaces. The claim that aggregates are only supported in NAT/Route mode is therefore incorrect.
- ✗
VLAN interfaces cannot be used in transparent mode.
Why it's wrong here
VLAN subinterfaces are fully supported in Transparent mode; they are commonly used to segment an 802.1Q trunk into multiple virtual L2 segments on a single physical or aggregate port. In Transparent mode, VLAN interfaces do not require IP addresses because the FortiGate acts as a transparent bridge, but each VLAN interface can still be assigned to zones and firewall policies. Therefore, saying VLAN interfaces cannot be used in Transparent mode is false.
- ✓
VLAN interfaces can be created on aggregate interfaces.
Why this is correct
FortiOS allows a VLAN interface to be created on top of an aggregate interface, enabling 802.1Q tagging across multiple physical links combined by LACP or static aggregation. This is common on trunk connections to switches, where the aggregate provides redundancy and bandwidth while the VLAN subinterfaces provide segmentation. Thus, aggregate interfaces are valid parent interfaces for VLAN creation.
- ✓
VLAN interfaces can have their own IP address and firewall policies.
Why this is correct
In NAT/Route mode, a VLAN interface is a logical Layer 3 interface that can be assigned its own IP address, netmask, and administrative settings, and it can be used as the source or destination interface in firewall policies. Each VLAN subinterface is treated as a separate interface, allowing distinct security zones, routing, and policy controls per VLAN. This statement is correct because it describes core VLAN interface capability.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.