NSE4 System and Network Administration Practice Question
A FortiGate in NAT/Route mode has multiple internal networks. The administrator wants to configure a loopback interface for management access. Which THREE statements about loopback interfaces are correct? (Choose three.)
⚠ Common exam trap
Test-takers frequently assume loopback interfaces cannot be used in firewall policies or must be tied to a physical port, but FortiGate treats them as fully functional interfaces for both routing and policy enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The loopback interface is always up regardless of physical link status
Option B is correct because a FortiGate loopback interface is a logical interface with no dependency on any physical link, so its operational state remains up even if physical ports go down. Option C is correct because the loopback's stable IP address is commonly configured as the source-ip for management protocols such as HTTPS, SSH, SNMP, and syslog, ensuring consistent management reachability. Option E is correct because loopback interfaces can be included in routing protocol configurations (for example, OSPF or BGP) and advertised as a stable router ID or network, which is a standard design practice. Option A is wrong because a loopback is a logical interface that is not bound to a physical port. Option D is wrong because loopback interfaces can absolutely be referenced in firewall policies as source or destination interfaces.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The loopback interface must be assigned to a physical port
Why it's wrong here
A loopback interface on a FortiGate is a purely virtual construct, created independently of any physical port. It does not map to a hardware NIC, and its existence is not tied to the presence or state of any physical interface. This allows administrators to assign stable IP addresses for management, routing, or VPN endpoints without consuming physical port resources.
- ✓
The loopback interface is always up regardless of physical link status
Why this is correct
Because a loopback interface has no physical hardware behind it, its link status is always administratively and operationally up as long as the FortiGate unit itself is powered on and running. This is a key advantage over physical interfaces, which may go down due to cable disconnection, switch failure, or negotiated link loss. The persistent up state makes loopback interfaces ideal for dynamic routing protocols and management sources that need a stable endpoint.
- ✓
The loopback interface can be used as a source IP for management traffic
Why this is correct
FortiGate allows the loopback interface IP to be configured as the source address for outbound management traffic such as syslog, SNMP, NetFlow, and RADIUS accounting. By setting the source IP to a loopback address, administrators ensure that management packets always originate from a fixed, predictable address, regardless of which physical interface the traffic actually egresses. This simplifies firewall rules and logging on external collectors because the source IP never changes.
- ✗
The loopback interface cannot be used for firewall policies
Why it's wrong here
Loopback interfaces are fully supported in firewall policies; they can be placed in zones and used as source or destination interfaces just like physical or VLAN interfaces. Traffic destined to the loopback IP arrives through the routing table, and policies referencing the loopback interface then apply to that traffic. This is commonly used to control management access or to host services such as SSL-VPN portals on a stable virtual interface.
- ✓
The loopback interface participates in routing protocols
Why this is correct
A loopback interface can hold an IP address and be injected into dynamic routing protocols such as OSPF, BGP, and RIP. Its always-up nature makes it a preferred source for BGP sessions and a stable router ID, as the loopback address does not fluctuate with physical link state. Many network designs use loopback IPs for iBGP peering and OSPF router-id configuration to avoid route flaps caused by interface downtime.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.