Courseiva

NSE4 Firewall Policies and NAT Practice Question

A FortiGate administrator wants to allow traffic from the internal network to a specific external server using its fully qualified domain name (FQDN) rather than an IP address, because the server's IP changes frequently. Which type of address object should the administrator create for the destination?

⚠ Common exam trap

Candidates often confuse Wildcard FQDN objects (used for domain pattern matching) with standard FQDN objects (used for DNS resolution to a single IP), leading them to select Option B incorrectly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

FQDN object

FQDN object. FortiGate FQDN objects resolve domain names to IP addresses dynamically, allowing the firewall to update the destination IP automatically when the server's IP changes. This is ideal for scenarios where the external server uses a fully qualified domain name and its IP address is not static.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Subnet object

    Why it's wrong here

    A subnet object defines a contiguous range of IP addresses using CIDR notation (e.g., 192.168.1.0/24), making it a static, broad match for any host within that range. It cannot resolve a domain name or track the IP of a single server that may change over time. If the server's IP changes, the administrator would need to manually update the subnet object, which is inflexible compared to an FQDN object.

  • ✗

    Wildcard FQDN object

    Why it's wrong here

    A wildcard FQDN object matches one or more domains sharing a common suffix, such as *.example.com, and is used to cover a group of dynamic subdomains. It does not resolve to a single, specific server IP, and its pattern matching could inadvertently include unintentional subdomains. For allowing traffic to one unique server, a regular FQDN object is required because it binds the policy to an exact hostname rather than a wildcard pattern.

  • ✗

    Geography object

    Why it's wrong here

    A geography object filters traffic based on the source or destination country, region, or continent using geolocation data, not on a specific host's IP address or hostname. It cannot identify one particular server unless that server is the only one in its country, which is impractical and risky. This object type is intended for broad geographic access control, not for granular host-level traffic enforcement.

  • ✓

    FQDN object

    Why this is correct

    An FQDN object represents a single, fully qualified domain name and dynamically resolves it to the current IP address at connection time. The FortiGate periodically refreshes the resolved IP addresses based on DNS TTL, so if the server's address changes, the policy remains valid without manual edits. This makes it the correct choice when allowing traffic to a specific server known by a domain name, especially when its IP is not static.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.