Drag or tap steps into the slots.
NSE4 System and Network Administration Practice Question
Drag and drop the steps to configure a static route on a FortiGate firewall into the correct order.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Enter config router static, then edit route with sequence number, then set destination, then set device, then set gateway, then end
Static routes on FortiGate are configured in the router static configuration context, requiring a sequence number, destination, device, and gateway.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enter config router static, then edit route with sequence number, then set destination, then set device, then set gateway, then end
Why this is correct
This order follows the FortiGate CLI: first enter the static route configuration context, then add or edit a route entry, then configure the destination network, outgoing interface, and next-hop gateway, and finally apply the changes with 'end'.
- ✗
Enter config router static, then edit route, then set gateway, then set destination, then set device, then end
Why it's wrong here
This order is incorrect because the gateway should be entered after defining the destination network and the outgoing interface. Although FortiGate CLI accepts set commands in any order, the device parameter establishes the egress interface that must be able to reach the gateway IP; assigning the gateway first risks referencing an interface that is not yet selected, leading to a route that fails validation or is unintentionally associated with the wrong interface. Additionally, the destination is the primary key for route matching, so it should precede optional fields like gateway for clarity and to avoid configuration errors.
- ✗
Enter config router static, then set destination, then set device, then set gateway, then edit route, then end
Why it's wrong here
This order is fundamentally flawed because the 'edit route' command must be executed before any 'set' statements to create or select the specific static route entry. Without entering the edit context, the set commands are issued at the 'config router static' table level, where no destination, device, or gateway attributes exist; FortiGate will return a syntax error or the settings will be discarded, so the route is never properly configured. Only after a valid 'edit <seq>' are the parameters accepted and stored for that route entry.
- ✗
Enter config router static, then edit route, then set device, then set gateway, then end, then set destination
Why it's wrong here
Setting the destination after 'end' means the change is applied outside the route edit context, so the destination will not be part of the route. The destination must be set before exiting the edit mode.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.