Courseiva

NSE4 System and Network Administration Practice Question

Drag and drop the steps to configure a static route on a FortiGate firewall into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enter config router static, then edit route with sequence number, then set destination, then set device, then set gateway, then end

Static routes on FortiGate are configured in the router static configuration context, requiring a sequence number, destination, device, and gateway.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enter config router static, then edit route with sequence number, then set destination, then set device, then set gateway, then end

    Why this is correct

    This order follows the FortiGate CLI: first enter the static route configuration context, then add or edit a route entry, then configure the destination network, outgoing interface, and next-hop gateway, and finally apply the changes with 'end'.

  • ✗

    Enter config router static, then edit route, then set gateway, then set destination, then set device, then end

    Why it's wrong here

    This order is incorrect because the gateway should be entered after defining the destination network and the outgoing interface. Although FortiGate CLI accepts set commands in any order, the device parameter establishes the egress interface that must be able to reach the gateway IP; assigning the gateway first risks referencing an interface that is not yet selected, leading to a route that fails validation or is unintentionally associated with the wrong interface. Additionally, the destination is the primary key for route matching, so it should precede optional fields like gateway for clarity and to avoid configuration errors.

  • ✗

    Enter config router static, then set destination, then set device, then set gateway, then edit route, then end

    Why it's wrong here

    This order is fundamentally flawed because the 'edit route' command must be executed before any 'set' statements to create or select the specific static route entry. Without entering the edit context, the set commands are issued at the 'config router static' table level, where no destination, device, or gateway attributes exist; FortiGate will return a syntax error or the settings will be discarded, so the route is never properly configured. Only after a valid 'edit <seq>' are the parameters accepted and stored for that route entry.

  • ✗

    Enter config router static, then edit route, then set device, then set gateway, then end, then set destination

    Why it's wrong here

    Setting the destination after 'end' means the change is applied outside the route edit context, so the destination will not be part of the route. The destination must be set before exiting the edit mode.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.