Courseiva

NSE7 Advanced Networking and SD-WAN Practice Question

A FortiGate administrator is integrating a FortiSwitch managed by the FortiGate. They want to configure a VLAN interface on the FortiSwitch for user traffic. Which configuration is required on the FortiGate?

⚠ Common exam trap

It's easy for candidates to confuse creating a VLAN on the FortiGate's own interfaces (using 'config system interface') with configuring a VLAN on a managed FortiSwitch, which requires the switch controller context.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a VLAN on the FortiSwitch under the switch controller and assign it to a port

When integrating a FortiSwitch managed by a FortiGate, VLANs for user traffic must be created under the switch controller on the FortiGate. This allows the FortiGate to push the VLAN configuration to the FortiSwitch, including assigning the VLAN to a specific port or port group. Option B correctly describes this process, as the switch controller manages the FortiSwitch as an extension of the FortiGate, not as a standalone device.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable DHCP relay on the FortiSwitch VLAN

    Why it's wrong here

    DHCP relay only forwards DHCP requests to a server; it neither creates nor tags a VLAN interface on the FortiSwitch, so the user VLAN still cannot carry traffic. It is tempting because relay is genuinely needed when clients on a switch VLAN must obtain addresses from a DHCP server elsewhere, which is a separate addressing concern from the VLAN interface itself.

  • ✓

    Configure a VLAN on the FortiSwitch under the switch controller and assign it to a port

    Why this is correct

    FortiLink-managed switches are configured through the FortiGate's switch controller. Creating the VLAN there and assigning it to a physical FortiSwitch port pushes the VLAN definition and membership down to the switch, which is the required step for user traffic separation.

  • ✗

    Use the config system interface to create a VLAN on the FortiGate and tag it on the trunk

    Why it's wrong here

    Creating a VLAN on the FortiGate and tagging it on the trunk configures the FortiGate side of the link, not the VLAN interface on the FortiSwitch that the scenario requires. It is tempting because FortiLink trunks do carry tagged VLANs, and this would be correct where the FortiGate terminates the VLAN rather than the managed switch.

  • ✗

    Create a VLAN subinterface on the FortiGate's port that connects to the FortiSwitch

    Why it's wrong here

    A VLAN subinterface on the FortiGate's physical port carries traffic between the FortiGate and the FortiSwitch, but the requirement is a VLAN interface on the FortiSwitch itself for user traffic. This is tempting because inter-VLAN routing on a FortiGate normally uses VLAN subinterfaces, which would be correct if the FortiGate, not the switch, terminated the user VLAN.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.