Courseiva

NSE4 System and Network Administration Practice Question

Which of the following FortiGate operating modes allows the firewall to act as a Layer 3 device, performing NAT and routing between interfaces?

⚠ Common exam trap

It's easy for candidates to confuse operational modes (NAT/Route vs. Transparent) with inspection modes (Flow-based vs. Proxy-based), leading candidates to incorrectly select Flow-based inspection mode as the answer for Layer 3 routing and NAT capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NAT/Route mode

NAT/Route mode (option B) is correct because it configures the FortiGate as a Layer 3 device with distinct interfaces in different subnets, enabling it to perform routing (forwarding packets based on routing table entries) and Network Address Translation (NAT) to translate private IP addresses to public IP addresses. This mode is the default and most common operational mode for perimeter firewalls, allowing policy-based routing and NAT rules to be applied between zones.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Flow-based inspection mode

    Why it's wrong here

    Flow-based inspection is a security profile processing mode, not a FortiGate operating mode. Operating modes are limited to NAT/Route and Transparent. In flow-based mode, the FortiGate uses a single-pass, session-based inspection engine to evaluate traffic against security profiles, leveraging hardware acceleration; however, this does not affect how the device routes or forwards traffic. Therefore, it cannot be the correct answer to a question about operating modes.

  • ✓

    NAT/Route mode

    Why this is correct

    NAT/Route mode is the default operating mode for FortiGate, where each interface is assigned an IP address and the device performs Layer 3 routing between networks. It also enables network address translation (NAT), allowing traffic to be translated between different address domains. This mode is distinctly different from Transparent mode, which operates at Layer 2 without routing or NAT. Because the question asks about an operating mode that supports routing and NAT, NAT/Route mode is the correct answer.

  • ✗

    VLAN mode

    Why it's wrong here

    VLAN mode is not a recognized FortiGate operating mode; instead, VLANs (802.1Q tagging) are implemented as sub-interfaces on physical interfaces. These VLAN sub-interfaces can be created and used in both NAT/Route and Transparent modes to segment traffic. The FortiGate does not have a separate operating mode dedicated to VLANs, as VLAN configuration is a feature within the existing operating modes. Therefore, VLAN mode is incorrect simply because it does not exist as an operating mode.

  • ✗

    Transparent mode

    Why it's wrong here

    Transparent mode operates as a transparent Layer 2 bridge, meaning the FortiGate does not perform IP routing or NAT. In this mode, all interfaces are on the same broadcast domain and the device processes traffic based on MAC addresses, like an inline firewall. While it is a valid operating mode, it explicitly lacks routing and NAT capabilities, which are the key features mentioned in the question. Thus, Transparent mode is incorrect because it does not provide routing or NAT functionality.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.