NSE7 Advanced Networking and SD-WAN Practice Question
A FortiGate is integrated with FortiSwitch and FortiAP. The administrator wants to manage both devices from the FortiGate GUI using the LAN edge management features. Which THREE conditions must be met for this integration to work?
⚠ Common exam trap
Many candidates assume transparent mode is acceptable for wireless management, but FortiGate must be in NAT mode to route CAPWAP traffic and provide the necessary network address translation for AP management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FortiAP must be in CAPWAP mode to connect to the FortiGate.
FortiAP must operate in CAPWAP (Control and Provisioning of Wireless Access Points) mode to establish a control tunnel to the FortiGate. This allows the FortiGate to act as the wireless controller, managing AP configuration, firmware, and client traffic via CAPWAP encapsulation. Without CAPWAP mode, the FortiAP cannot be discovered or managed through the FortiGate's LAN edge management features.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
FortiAP must be in CAPWAP mode to connect to the FortiGate.
Why this is correct
FortiAP uses CAPWAP to tunnel traffic to the FortiGate.
- ✓
The FortiGate must be in NAT mode.
Why this is correct
NAT mode is required for managing FortiSwitch and FortiAP.
- ✓
FortiSwitch must be in the same Layer 2 domain as the FortiGate management interface.
Why this is correct
For direct management, FortiSwitch must be reachable at Layer 2.
- ✗
The FortiGate must operate in transparent mode.
Why it's wrong here
Transparent mode is not supported; NAT mode is required.
- ✗
The FortiGate must have a separate VDOM for each managed device.
Why it's wrong here
A single VDOM can manage multiple devices.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.