Courseiva

NSE4 Firewall Policies and NAT Practice Question

A FortiGate administrator needs to allow all internal users (10.0.0.0/8) to access a web server in the DMZ (192.168.1.100) using HTTPS. The administrator wants to apply a web filter profile to block malicious URLs while allowing legitimate traffic. Which of the following is the correct policy configuration?

⚠ Common exam trap

Many exam-takers confuse the service requirement (HTTPS vs HTTP) or assume that applying a web filter profile to HTTPS traffic works without SSL inspection, leading them to select option B or A, or they mistakenly think a DENY action with a web filter profile can still allow traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Policy: source=internal, destination=DMZ, service=HTTPS, action=ACCEPT, web filter profile=default

The policy must match the HTTPS service (TCP/443) to allow encrypted web traffic to the DMZ web server, and the web filter profile is applied to inspect the HTTPS traffic for malicious URLs. The default web filter profile can block malicious URLs while allowing legitimate HTTPS traffic, provided SSL inspection is configured to enable content filtering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Policy: source=internal, destination=DMZ, service=ALL, action=ACCEPT, web filter profile=default

    Why it's wrong here

    Selecting service=ALL with action=ACCEPT creates a wide-open policy that permits every IP protocol and port from internal to DMZ, far beyond the requested HTTPS traffic. This violates least-privilege access, exposes the DMZ servers to services such as telnet, SMB, and arbitrary TCP/UDP ports, and the attached web filter profile can only inspect HTTP/HTTPS, so most of the allowed traffic bypasses content filtering. The administrator should narrow the service to HTTPS instead of relying on a catch-all rule.

  • ✗

    Policy: source=internal, destination=DMZ, service=HTTP, action=ACCEPT, web filter profile=default

    Why it's wrong here

    The HTTP service object in FortiOS is defined as TCP port 80, whereas the requirement is to allow encrypted HTTPS web traffic, which uses TCP port 443. Since the policy only allows port 80, HTTPS connection attempts to the DMZ servers will be silently dropped or rejected, and the web filter profile will only see unencrypted HTTP sessions, not the intended secure traffic. The destination service must be HTTPS, not HTTP, to match the actual request.

  • ✓

    Policy: source=internal, destination=DMZ, service=HTTPS, action=ACCEPT, web filter profile=default

    Why this is correct

    This policy precisely matches the requirement: the HTTPS service object maps to TCP port 443, allowing encrypted web sessions from internal users to the DMZ, while action=ACCEPT forwards the traffic. The web filter profile is applied after the traffic is accepted, enabling URL and content inspection of the HTTPS sessions, provided that SSL inspection (deep or certificate-based) is already configured on the FortiGate. This is the only option that both permits the required traffic and enforces the intended security control.

  • ✗

    Policy: source=internal, destination=DMZ, service=HTTPS, action=DENY, web filter profile=default

    Why it's wrong here

    Setting action=DENY for HTTPS traffic means the FortiGate will drop all packets destined for TCP 443, so users cannot reach the DMZ web servers at all. In a deny policy, FortiOS does not inspect the content because the traffic is discarded before any web filter or UTM processing can occur, making the web filter profile meaningless. The requirement explicitly asks to allow internal users, so a deny action directly contradicts the stated objective.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.