Courseiva

NSE4 System and Network Administration Practice Question

A FortiGate administrator needs to configure a policy route to send all traffic destined to 10.10.10.0/24 out through interface port3 instead of the default route. Which configuration steps are necessary?

⚠ Common exam trap

Test-takers frequently confuse firewall policies (which control access and NAT) with policy routes (which control forwarding decisions), leading candidates to incorrectly select Option A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a policy route under 'config router policy' with destination 10.10.10.0/24 and output interface port3

Policy routes override the routing table for specific traffic based on criteria like source, destination, or protocol. Option D correctly configures a policy route under 'config router policy' to match destination 10.10.10.0/24 and set the output interface to port3, ensuring that traffic is forwarded out port3 regardless of the default route.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a firewall policy with source interface any, destination 10.10.10.0/24, and set the egress interface to port3

    Why it's wrong here

    A firewall policy is evaluated only after the routing decision has already been made, and it cannot alter the egress interface for traffic destined to 10.10.10.0/24. Setting an outgoing interface in a policy does not manipulate the routing table or override the next-hop selection; it merely restricts which interface the policy applies to. Even if you set source interface any and destination 10.10.10.0/24, the actual path taken by packets is still determined by the static or dynamic routes, so this action would not achieve policy-based routing.

  • ✗

    Create a static route for 10.10.10.0/24 with a lower distance pointing to port3

    Why it's wrong here

    Creating a static route for 10.10.10.0/24 with a lower distance would send that traffic toward port3, but this is a conventional destination-based routing entry, not a policy route. Policy routes are configured under 'config router policy' and are designed to override the routing table based on additional criteria such as source IP, protocol, or interface, which a static route cannot do. Since the question specifically asks for a policy route, using a static route is an incorrect approach even though it might achieve similar connectivity for that subnet.

  • ✗

    Set the default gateway to port3 and remove the existing default route

    Why it's wrong here

    Changing the default gateway to port3 and removing the existing default route would affect all traffic without a more-specific route, not just traffic to 10.10.10.0/24. This would break connectivity for other destinations and does not provide the selective, policy-based routing that is required. Moreover, policy routes allow you to direct specific traffic (based on destination, source, etc.) while leaving all other routing decisions unchanged; this option is a blunt instrument that creates an outage instead of a targeted routing rule.

  • ✓

    Configure a policy route under 'config router policy' with destination 10.10.10.0/24 and output interface port3

    Why this is correct

    The correct way to route traffic to 10.10.10.0/24 through port3 based on a policy is to configure a policy route in the 'config router policy' section. In FortiOS, policy routes are evaluated before the routing table and can match on source and destination addresses, protocols, and incoming interfaces, then set an explicit output interface. This gives the administrator precise control over traffic engineering without altering the normal routing table or affecting other traffic. Thus, 'config router policy' with destination 10.10.10.0/24 and output interface port3 is the correct implementation.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.