nerdexam
Fortinet

NSE4 · Question #316

Which statements correctly describe transparent mode operation? (Choose three.)

The correct answer is C. It permits inline traffic inspection and firewalling without changing the IP scheme of the network. D. Ethernet packets are forwarded based on destination MAC addresses, not IP addresses. E. The FortiGate acts as transparent bridge and forwards traffic at Layer-2. In transparent mode, a FortiGate operates as a Layer-2 bridge, forwarding traffic based on MAC addresses, which allows it to inspect and firewall inline traffic without requiring changes to the network's IP addressing scheme.

Submitted by ricky.ec· Apr 18, 2026FortiGate Deployment and System Configuration

Question

Which statements correctly describe transparent mode operation? (Choose three.)

Options

  • AAll interfaces of the transparent mode FortiGate device must be on different IP subnets.
  • BThe transparent FortiGate is visible to network hosts in an IP traceroute.
  • CIt permits inline traffic inspection and firewalling without changing the IP scheme of the network.
  • DEthernet packets are forwarded based on destination MAC addresses, not IP addresses.
  • EThe FortiGate acts as transparent bridge and forwards traffic at Layer-2.

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    7% (2)
  • C
    90% (27)

Why each option

In transparent mode, a FortiGate operates as a Layer-2 bridge, forwarding traffic based on MAC addresses, which allows it to inspect and firewall inline traffic without requiring changes to the network's IP addressing scheme.

AAll interfaces of the transparent mode FortiGate device must be on different IP subnets.

In transparent mode, all interfaces that form the bridge must be on the *same* IP subnet, as the device is forwarding traffic at Layer 2 within that segment.

BThe transparent FortiGate is visible to network hosts in an IP traceroute.

Because a transparent mode FortiGate operates at Layer 2 and does not perform IP routing, it is typically invisible to network hosts in an IP traceroute.

CIt permits inline traffic inspection and firewalling without changing the IP scheme of the network.Correct

Transparent mode allows the FortiGate to be inserted into an existing network segment to perform security functions like inspection and firewalling without requiring any changes to the IP addressing or routing configuration of the network.

DEthernet packets are forwarded based on destination MAC addresses, not IP addresses.Correct

In transparent mode, the FortiGate functions as a Layer-2 bridge, meaning it processes and forwards Ethernet frames based on their destination MAC addresses, rather than routing based on IP addresses.

EThe FortiGate acts as transparent bridge and forwards traffic at Layer-2.Correct

The FortiGate in transparent mode behaves like an invisible Layer-2 bridge, connecting two network segments and passing traffic between them while applying security policies.

Concept tested: FortiGate transparent mode operation

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/464817/operation-modes

Topics

#Transparent mode#FortiGate operation#Layer 2 bridging#Network deployment

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice