Drag or tap steps into the slots.
NSE4 Security Profiles Practice Question
Drag and drop the steps to configure a VLAN interface on FortiGate into the correct order.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Create VLAN interface, then configure parent interface and VLAN ID, then assign IP address, then enable administrative access.
VLAN interfaces require a physical parent, VLAN ID, IP address, and optional administrative access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create VLAN interface, then configure parent interface and VLAN ID, then assign IP address, then enable administrative access.
Why this is correct
This is the correct order because in FortiOS, a VLAN interface is a subinterface object that must first exist before any of its attributes can be set. You create it by entering the interface configuration and editing a name, then you bind it to a physical parent interface and assign an 802.1Q VLAN ID. Only after the interface is bound can you give it an IP address, and finally you enable administrative access (e.g., HTTPS, SSH, ping) separately per interface.
- ✗
Assign IP address, then create VLAN interface, then configure parent interface and VLAN ID, then enable administrative access.
Why it's wrong here
You cannot assign an IP address before creating the VLAN interface because an IP address is a property of the interface object itself. In the FortiOS CLI, you must 'edit' the interface first to create it, and only then can you use 'set ip'. Attempting to assign an IP to a non-existent interface produces an error and leaves no usable configuration, making this sequence fundamentally impossible.
- ✗
Create VLAN interface, then assign IP address, then configure parent interface and VLAN ID, then enable administrative access.
Why it's wrong here
While creating the interface first is correct, assigning an IP address before configuring the parent interface and VLAN ID is wrong because the VLAN subinterface is not yet bound to a physical port or an 802.1Q tag. Without that binding, the interface cannot carry traffic, and the IP address remains on an incomplete, operationally down interface. Firewall policies and routing that reference this interface will not work until the parent and VLAN ID are set.
- ✗
Configure parent interface and VLAN ID, then create VLAN interface, then assign IP address, then enable administrative access.
Why it's wrong here
You cannot configure the parent interface and VLAN ID before creating the VLAN interface because those settings are attributes stored within the VLAN interface node. In FortiOS, you must first 'edit' the interface name under 'config system interface' to create it, and then you can apply 'set interface' and 'set vlanid'. Configuring properties of an object that does not yet exist is impossible and will be rejected by the CLI.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.