Courseiva

NSE4 System and Network Administration Practice Question

An administrator is configuring a FortiGate in a transparent mode. Which of the following features is NOT available in transparent mode?

⚠ Common exam trap

Test-takers frequently assume security features like IPS or AV require Layer 3 routing, but they actually operate at higher layers and work in transparent mode, while NAT is the only option that explicitly depends on Layer 3 functionality.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Source NAT

In transparent mode, the FortiGate operates as a Layer 2 bridge without routing capabilities, meaning it cannot perform Source NAT (SNAT) because SNAT requires Layer 3 routing to translate source IP addresses. Transparent mode does not have an IP address on its interfaces for routing, so features dependent on Layer 3 forwarding, such as NAT, are unavailable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Source NAT

    Why this is correct

    Source NAT is not available in transparent mode because the FortiGate acts as a Layer 2 bridge, forwarding frames based on MAC addresses without performing any Layer 3 routing decisions. NAT requires modifying source IP addresses during packet routing, which is inherently a Layer 3 function, so it cannot be applied to traffic that passes through transparently.

  • ✗

    VLAN tagging

    Why it's wrong here

    VLAN tagging is fully supported in transparent mode because the FortiGate can bridge 802.1Q tagged frames between different VLAN segments. It inspects and forwards these Layer 2 frames while preserving the VLAN tags, enabling traffic separation and inter-VLAN communication without requiring IP routing.

  • ✗

    Intrusion Prevention System (IPS)

    Why it's wrong here

    IPS is available in transparent mode because it inspects traffic at the application and protocol levels, regardless of how the traffic is forwarded. The FortiGate can detect and block intrusion attempts in bridged mode using flow-based or proxy-based inspection, as it does not need to alter IP packet routing to enforce IPS policies.

  • ✗

    Security profiles (AV, web filter)

    Why it's wrong here

    Security profiles such as antivirus and web filtering operate on the content of the traffic, typically at the application layer, and can be applied in transparent mode by intercepting and scanning packets. Whether through flow-based inspection or offloading to a proxy, these profiles do not depend on Layer 3 routing, making them fully functional in a Layer 2 deployment.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.