Courseiva

NSE4 System and Network Administration Practice Question

A FortiGate is operating in transparent mode. The administrator needs to configure a new VLAN interface for segmenting traffic. Which statement about VLAN interfaces in transparent mode is correct?

⚠ Common exam trap

Test-takers frequently assume VLAN interfaces always require IP addresses for operation, confusing transparent mode's layer-2 behavior with NAT/Route mode's layer-3 routing requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VLAN interfaces can be created on physical interfaces and are layer-2 only, requiring no IP addresses for traffic forwarding.

In transparent mode, FortiGate acts as a layer-2 bridge, forwarding traffic based on MAC addresses. VLAN interfaces can be created on physical interfaces to segment traffic at layer 2, and they do not require IP addresses for forwarding; IP addresses are only needed for management access if desired.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VLAN interfaces require IP addresses and act as routed interfaces in transparent mode.

    Why it's wrong here

    In transparent mode, FortiGate acts as a transparent bridge, so VLAN interfaces are created as Layer-2 subinterfaces that forward traffic based on MAC addresses, not IP addresses. Assigning an IP to these interfaces would be an administrative exception, not a forwarding requirement, and they never act as routed interfaces. Therefore, the claim that they require IPs and perform routing confuses transparent-mode behavior with NAT/Route mode.

  • ✓

    VLAN interfaces can be created on physical interfaces and are layer-2 only, requiring no IP addresses for traffic forwarding.

    Why this is correct

    Correct: In transparent mode, you can create VLAN subinterfaces on physical ports to segment the Layer-2 network. These interfaces operate purely at Layer 2, bridging frames between 802.1Q-tagged segments without any IP configuration for forwarding. A management IP is optional and only for administrative access, not for the VLAN interface's traffic path. This design lets the firewall apply security policies to VLAN traffic while remaining invisible to Layer 3 routing.

  • ✗

    VLAN interfaces can only be created on physical interfaces, and each VLAN requires a separate IP address in the management VDOM.

    Why it's wrong here

    The statement erroneously implies that each VLAN interface must have a separate IP address in a 'management VDOM.' In transparent mode, VLAN interfaces are data-plane interfaces that need no IPs; management access is typically via a single management IP or a dedicated management interface, not per-VLAN IPs. Additionally, VLAN subinterfaces are not limited to physical ports only—they can also be created on aggregate interfaces—but the more fundamental error is the IP requirement, which is absent in true Layer-2 transparent operation.

  • ✗

    VLAN interfaces are not supported in transparent mode; the administrator must switch to NAT/Route mode.

    Why it's wrong here

    Transparent mode fully supports VLAN interfaces, so no switch to NAT/Route mode is necessary. The FortiGate bridges 802.1Q-tagged frames across its interfaces and applies firewall policies at Layer 2, optionally using VLANs to isolate broadcast domains. Forcing NAT/Route mode would defeat the purpose of deploying the device transparently and would require IP reconfiguration, which is why this option is incorrect.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.