NSE4 System and Network Administration Practice Question
A FortiGate administrator needs to configure a policy route to send all traffic destined to 10.10.10.0/24 out through interface port3 instead of the default route. Which configuration steps are necessary?
⚠ Common exam trap
Test-takers frequently confuse firewall policies (which control access and NAT) with policy routes (which control forwarding decisions), leading candidates to incorrectly select Option A.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a policy route under 'config router policy' with destination 10.10.10.0/24 and output interface port3
Policy routes override the routing table for specific traffic based on criteria like source, destination, or protocol. Option D correctly configures a policy route under 'config router policy' to match destination 10.10.10.0/24 and set the output interface to port3, ensuring that traffic is forwarded out port3 regardless of the default route.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a firewall policy with source interface any, destination 10.10.10.0/24, and set the egress interface to port3
Why it's wrong here
A firewall policy is evaluated only after the routing decision has already been made, and it cannot alter the egress interface for traffic destined to 10.10.10.0/24. Setting an outgoing interface in a policy does not manipulate the routing table or override the next-hop selection; it merely restricts which interface the policy applies to. Even if you set source interface any and destination 10.10.10.0/24, the actual path taken by packets is still determined by the static or dynamic routes, so this action would not achieve policy-based routing.
- ✗
Create a static route for 10.10.10.0/24 with a lower distance pointing to port3
Why it's wrong here
Creating a static route for 10.10.10.0/24 with a lower distance would send that traffic toward port3, but this is a conventional destination-based routing entry, not a policy route. Policy routes are configured under 'config router policy' and are designed to override the routing table based on additional criteria such as source IP, protocol, or interface, which a static route cannot do. Since the question specifically asks for a policy route, using a static route is an incorrect approach even though it might achieve similar connectivity for that subnet.
- ✗
Set the default gateway to port3 and remove the existing default route
Why it's wrong here
Changing the default gateway to port3 and removing the existing default route would affect all traffic without a more-specific route, not just traffic to 10.10.10.0/24. This would break connectivity for other destinations and does not provide the selective, policy-based routing that is required. Moreover, policy routes allow you to direct specific traffic (based on destination, source, etc.) while leaving all other routing decisions unchanged; this option is a blunt instrument that creates an outage instead of a targeted routing rule.
- ✓
Configure a policy route under 'config router policy' with destination 10.10.10.0/24 and output interface port3
Why this is correct
The correct way to route traffic to 10.10.10.0/24 through port3 based on a policy is to configure a policy route in the 'config router policy' section. In FortiOS, policy routes are evaluated before the routing table and can match on source and destination addresses, protocols, and incoming interfaces, then set an explicit output interface. This gives the administrator precise control over traffic engineering without altering the normal routing table or affecting other traffic. Thus, 'config router policy' with destination 10.10.10.0/24 and output interface port3 is the correct implementation.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.