Courseiva

NSE4 System and Network Administration Practice Question

An administrator configures a FortiGate in transparent mode. Which of the following is correct regarding transparent mode operation?

⚠ Common exam trap

Candidates often confuse transparent mode with NAT/Route mode, assuming that all FortiGate modes perform NAT or require IP addresses on each interface, when in fact transparent mode is purely Layer 2 and does not modify IP headers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The FortiGate is invisible to end devices and does not modify IP addresses.

In transparent mode, the FortiGate operates as a Layer 2 bridge, forwarding traffic based on MAC addresses without performing any IP-level modifications. This means it does not perform NAT, and end devices are unaware of its presence, making option D correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The FortiGate performs NAT between its interfaces.

    Why it's wrong here

    In transparent mode, the FortiGate operates as a Layer 2 bridge, forwarding frames based on MAC addresses without altering IP headers. NAT is a Layer 3 function that rewrites source/destination addresses, which would break the device's transparency and is only used in routed/NAT mode. Therefore, the statement that the FortiGate performs NAT between interfaces is incorrect.

  • ✗

    The FortiGate interfaces can be on different subnets.

    Why it's wrong here

    Transparent mode requires all participating interfaces to belong to the same IP subnet and broadcast domain because the FortiGate bridges traffic between them. If interfaces were on different subnets, the device would need routing capabilities, which are explicitly disabled in transparent mode. This fundamental restriction differentiates it from routed mode, where interfaces can indeed span multiple subnets.

  • ✗

    The FortiGate requires a management IP on each interface.

    Why it's wrong here

    In transparent mode, interfaces do not require individual IP addresses because they operate purely at Layer 2. The FortiGate uses a single dedicated management IP (often on a management interface or a VLAN) for administrative access, leaving data interfaces IP-less. Requiring an IP on each interface would be unnecessary and would compromise the device's transparency.

  • ✓

    The FortiGate is invisible to end devices and does not modify IP addresses.

    Why this is correct

    Transparent mode is designed to be invisible to end devices, acting as an inline security appliance without modifying IP addresses or making routing decisions. The FortiGate inspects frames at Layer 2, allowing IP packets to pass through unchanged, which is why it is often deployed without requiring any network redesign. This invisibility is the defining characteristic that makes the statement correct.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.