NSE7 Advanced Networking and SD-WAN Practice Question
A FortiGate administrator is integrating a FortiSwitch managed by the FortiGate. They want to configure a VLAN interface on the FortiSwitch for user traffic. Which configuration is required on the FortiGate?
⚠ Common exam trap
It's easy for candidates to confuse creating a VLAN on the FortiGate's own interfaces (using 'config system interface') with configuring a VLAN on a managed FortiSwitch, which requires the switch controller context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a VLAN on the FortiSwitch under the switch controller and assign it to a port
When integrating a FortiSwitch managed by a FortiGate, VLANs for user traffic must be created under the switch controller on the FortiGate. This allows the FortiGate to push the VLAN configuration to the FortiSwitch, including assigning the VLAN to a specific port or port group. Option B correctly describes this process, as the switch controller manages the FortiSwitch as an extension of the FortiGate, not as a standalone device.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable DHCP relay on the FortiSwitch VLAN
Why it's wrong here
DHCP relay only forwards DHCP requests to a server; it neither creates nor tags a VLAN interface on the FortiSwitch, so the user VLAN still cannot carry traffic. It is tempting because relay is genuinely needed when clients on a switch VLAN must obtain addresses from a DHCP server elsewhere, which is a separate addressing concern from the VLAN interface itself.
- ✓
Configure a VLAN on the FortiSwitch under the switch controller and assign it to a port
Why this is correct
FortiLink-managed switches are configured through the FortiGate's switch controller. Creating the VLAN there and assigning it to a physical FortiSwitch port pushes the VLAN definition and membership down to the switch, which is the required step for user traffic separation.
- ✗
Use the config system interface to create a VLAN on the FortiGate and tag it on the trunk
Why it's wrong here
Creating a VLAN on the FortiGate and tagging it on the trunk configures the FortiGate side of the link, not the VLAN interface on the FortiSwitch that the scenario requires. It is tempting because FortiLink trunks do carry tagged VLANs, and this would be correct where the FortiGate terminates the VLAN rather than the managed switch.
- ✗
Create a VLAN subinterface on the FortiGate's port that connects to the FortiSwitch
Why it's wrong here
A VLAN subinterface on the FortiGate's physical port carries traffic between the FortiGate and the FortiSwitch, but the requirement is a VLAN interface on the FortiSwitch itself for user traffic. This is tempting because inter-VLAN routing on a FortiGate normally uses VLAN subinterfaces, which would be correct if the FortiGate, not the switch, terminated the user VLAN.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.