NSE4 Firewall Policies and NAT Practice Question
A FortiGate administrator needs to block all traffic from a specific IP address (10.0.0.100) to the internet, but allow all other internal users. The administrator has created a firewall policy with source=10.0.0.100, destination=all, service=all, action=DENY, and placed it at the top of the policy list. Which TWO additional steps should the administrator take to ensure the block is effective? (Choose two.)
⚠ Common exam trap
The trap here is that candidates often forget that new policies are disabled by default, and they may overlook the importance of policy order when a deny rule is placed at the top but a previous ACCEPT rule exists for the same source.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the policy
A newly created firewall policy in FortiGate is disabled by default. The administrator must explicitly enable the policy for it to be enforced. Without enabling, the deny rule will not process traffic, leaving the block ineffective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable the policy
Why this is correct
In FortiGate, firewall policies are created in a disabled state by default unless explicitly enabled at creation. A disabled policy is not evaluated in the policy lookup, so even if it matches the source/destination/service, traffic will not be denied. For the deny action to be enforced, the policy must have its status set to 'enable' so the FortiOS kernel includes it in the ordered rule evaluation.
- ✗
Configure an IP Pool for the deny policy
Why it's wrong here
IP Pools are used for source NAT (SNAT) when a policy action is ACCEPT and you want to translate the source IP. Deny policies do not perform NAT or use IP pools; the deny action simply discards the packet without any translation. Configuring an IP pool on a deny policy is irrelevant and has no effect on blocking traffic.
- ✗
Add a schedule to the policy for business hours
Why it's wrong here
A schedule defines the time range when a policy is active. If you set a business-hours schedule, the deny policy would only block 10.0.0.100 during those hours; outside that window the policy would not be checked and traffic could be allowed by other policies. For a constant block, the schedule should be set to 'always' (i.e., none or 'always'), not business hours.
- ✓
Ensure no other policy above this one allows traffic from 10.0.0.100
Why this is correct
Firewall policies in FortiGate are evaluated sequentially from the top of the policy list, and the first policy that matches the traffic's source/destination/service is applied. If a policy higher in the sequence (i.e., with a lower policy ID) already permits traffic from 10.0.0.100, the deny policy will never be reached, so the traffic will be allowed. This is why the deny rule must be placed above any allow rule that would otherwise match, or the allow rule must be removed/modified to avoid matching.
- ✗
Set the action to ACCEPT
Why it's wrong here
The action field determines what happens when the policy matches. 'ACCEPT' means the traffic is permitted through the firewall, which is the exact opposite of blocking. To block, the action must be 'DENY' (or 'REJECT' with a reply). Setting ACCEPT would allow the traffic, rendering the policy useless for blocking.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.