NSE4 System and Network Administration Practice Question
An administrator needs to configure a loopback interface on a FortiGate for management purposes. Which of the following is true regarding loopback interfaces?
⚠ Common exam trap
Watch out — candidates often assume loopback interfaces are only for routing protocols or require a physical link, but FortiGate allows them to serve as stable management endpoints independent of physical interface status.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Loopback interfaces are virtual and can be used as source IP for management traffic.
Loopback interfaces are virtual interfaces that are always up and do not depend on the physical link state. They can be assigned an IP address and used as the source IP for management traffic (e.g., SNMP, syslog, NTP, or administrative access), ensuring consistent reachability even if physical interfaces fail. This makes option A correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Loopback interfaces are virtual and can be used as source IP for management traffic.
Why this is correct
Loopback interfaces in FortiGate are virtual, software-only interfaces that are always up and not tied to any physical port. They can be assigned an IP address and configured as the source IP for management traffic, such as syslog, SNMP, NTP, or administrative HTTPS/SSH sessions. Because they are independent of physical link states, they provide a stable management address even when a physical interface fails.
- ✗
Loopback interfaces require a physical port to be associated.
Why it's wrong here
Loopback interfaces are logical constructs created purely in the FortiGate configuration, so they do not need to be bound to a physical port or interface. They exist as long as the firewall is running and do not rely on hardware link states. In contrast, physical interfaces require an actual port to be present and administratively up for traffic to pass. Therefore, the assertion that a physical port must be associated is incorrect.
- ✗
Loopback interfaces cannot be used in firewall policies.
Why it's wrong here
Loopback interfaces are fully supported as interface objects in firewall policies, just like physical or VLAN interfaces. A policy can specify a loopback as the source or destination interface, allowing or denying traffic to and from that virtual interface. For example, you can create a policy with the loopback as the destination to restrict management access or to terminate IPsec VPN traffic. Thus, the claim that they cannot be used in policies is false.
- ✗
Loopback interfaces are only available in transparent mode.
Why it's wrong here
FortiGate loopback interfaces are available in both NAT and transparent modes, so the idea that they are limited to transparent mode is incorrect. In NAT mode, they are commonly used for management, routing protocol peering, and as stable tunnel endpoints. In transparent mode, they can also be configured for management access, though their use case is more limited. Therefore, this option is wrong because it incorrectly restricts loopback availability to only one operating mode.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.