Courseiva
Firewall Policies and NAThardMultiple SelectObjective-mapped

NSE4 Firewall Policies and NAT Practice Question

A FortiGate administrator is configuring a policy-based routing (PBR) rule to send all traffic from the 'Engineering' VLAN (10.1.0.0/16) to a dedicated internet link through gateway 203.0.113.1. The administrator also wants to apply a traffic shaper to limit bandwidth. Which THREE configuration tasks must be performed?

⚠ Common exam trap

Watch out — candidates often think SD-WAN is required for PBR or that Central NAT is mandatory, when in fact PBR and traffic shaping are independent features that can be configured without SD-WAN or Central NAT.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Define a traffic shaper object with the desired bandwidth limits

A traffic shaper object must first be defined with the desired bandwidth limits (e.g., maximum rate, burst size) before it can be applied to a firewall policy. Without this object, the shaper cannot be referenced or enforced.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Define a traffic shaper object with the desired bandwidth limits

    Why this is correct

    The shaper must exist before it can be applied in a firewall policy.

  • Enable SD-WAN on the FortiGate

    Why it's wrong here

    SD-WAN is not required; PBR works independently of SD-WAN.

  • Configure Central NAT to translate the source IP

    Why it's wrong here

    NAT is separate; PBR does not require NAT, though NAT may be needed for internet access. However, the question focuses on PBR and shaping.

  • Create a policy-based route with source 10.1.0.0/16 and gateway 203.0.113.1

    Why this is correct

    PBR rule defines the routing override for matching traffic.

  • Create a firewall policy allowing traffic from Engineering VLAN to internet and apply the traffic shaper

    Why this is correct

    The firewall policy permits the traffic and attaches the shaper to enforce bandwidth limits.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every NSE4 question from scratch — 282 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.