Courseiva

NSE4 System and Network Administration Practice Question

A FortiGate administrator needs to configure a VLAN interface and an aggregate interface. Which THREE statements are correct regarding these interface types?

⚠ Common exam trap

A common mix-up: candidates confuse the mode restrictions for VLANs and aggregates, incorrectly assuming VLANs cannot be used in Transparent mode or that aggregates are limited to NAT/Route mode, when in fact both interface types have broader support.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Aggregate interfaces require at least one physical member to be up.

An aggregate interface (LAG) requires at least one physical member port to be administratively and operationally up for the aggregate itself to be considered up. If all member ports are down, the aggregate interface goes down, which is a fundamental behavior of link aggregation groups (LAGs) per IEEE 802.3ad.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Aggregate interfaces require at least one physical member to be up.

    Why this is correct

    For an aggregate interface to pass traffic, FortiOS requires at least one physical member interface to be administratively enabled and have a live link; if every member is down, the aggregate port is marked down. This is the basis of the correct answer because it accurately reflects a physical requirement for aggregate interfaces in FortiOS.

  • ✗

    Aggregate interfaces are only supported in NAT/Route mode.

    Why it's wrong here

    Link aggregation is a physical-layer redundancy technique available in both NAT/Route and Transparent modes on FortiGate. In Transparent mode, aggregate interfaces can be used to carry 802.1Q VLAN trunks just like any physical interface, and there is no operating-mode restriction on 802.3ad or static aggregate interfaces. The claim that aggregates are only supported in NAT/Route mode is therefore incorrect.

  • ✗

    VLAN interfaces cannot be used in transparent mode.

    Why it's wrong here

    VLAN subinterfaces are fully supported in Transparent mode; they are commonly used to segment an 802.1Q trunk into multiple virtual L2 segments on a single physical or aggregate port. In Transparent mode, VLAN interfaces do not require IP addresses because the FortiGate acts as a transparent bridge, but each VLAN interface can still be assigned to zones and firewall policies. Therefore, saying VLAN interfaces cannot be used in Transparent mode is false.

  • ✓

    VLAN interfaces can be created on aggregate interfaces.

    Why this is correct

    FortiOS allows a VLAN interface to be created on top of an aggregate interface, enabling 802.1Q tagging across multiple physical links combined by LACP or static aggregation. This is common on trunk connections to switches, where the aggregate provides redundancy and bandwidth while the VLAN subinterfaces provide segmentation. Thus, aggregate interfaces are valid parent interfaces for VLAN creation.

  • ✓

    VLAN interfaces can have their own IP address and firewall policies.

    Why this is correct

    In NAT/Route mode, a VLAN interface is a logical Layer 3 interface that can be assigned its own IP address, netmask, and administrative settings, and it can be used as the source or destination interface in firewall policies. Each VLAN subinterface is treated as a separate interface, allowing distinct security zones, routing, and policy controls per VLAN. This statement is correct because it describes core VLAN interface capability.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.