nerdexam
Fortinet

NSE4 · Question #490

Which of the following statements is true regarding a FortiGate device operating in transparent mode? (Choose three.)

The correct answer is A. It acts as a layer 2 bridge C. It forwards frames using the destination MAC address. E. It can perform content inspection (antivirus, web filtering, etc). In transparent mode, a FortiGate acts as a Layer 2 bridge, forwarding frames based on MAC addresses, while still performing advanced content inspection like antivirus and web filtering.

Submitted by ahmad_uae· Apr 18, 2026FortiGate Deployment and System Configuration

Question

Which of the following statements is true regarding a FortiGate device operating in transparent mode? (Choose three.)

Options

  • AIt acts as a layer 2 bridge
  • BIt acts as a layer 3 router
  • CIt forwards frames using the destination MAC address.
  • DIt forwards packets using the destination IP address.
  • EIt can perform content inspection (antivirus, web filtering, etc)

How the community answered

(48 responses)
  • A
    88% (42)
  • B
    4% (2)
  • D
    8% (4)

Why each option

In transparent mode, a FortiGate acts as a Layer 2 bridge, forwarding frames based on MAC addresses, while still performing advanced content inspection like antivirus and web filtering.

AIt acts as a layer 2 bridgeCorrect

When operating in transparent mode, a FortiGate device functions as a Layer 2 bridge, seamlessly integrating into an existing network segment without requiring changes to IP addressing or routing.

BIt acts as a layer 3 router

A FortiGate in transparent mode does not perform Layer 3 routing functions; it operates at Layer 2, passing traffic based on MAC addresses.

CIt forwards frames using the destination MAC address.Correct

As a Layer 2 bridge, the FortiGate in transparent mode forwards network traffic by examining the destination MAC address in the Ethernet frame, making it invisible to network devices.

DIt forwards packets using the destination IP address.

Forwarding packets based on destination IP address is a function of a Layer 3 router, which is not the operational mode of a FortiGate in transparent mode.

EIt can perform content inspection (antivirus, web filtering, etc)Correct

Despite its Layer 2 transparent operation, the FortiGate retains its full Next-Generation Firewall capabilities, including deep packet inspection for services such as antivirus, web filtering, and intrusion prevention.

Concept tested: FortiGate transparent mode operation

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/466580/operational-modes

Topics

#FortiGate Transparent Mode#Layer 2 Bridging#Content Inspection#Network Modes

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice