NSE4 Firewall Policies and NAT Practice Question
A FortiGate administrator wants to create a firewall policy that matches traffic based on the destination domain name (e.g., *.example.com). Which type of address object should be used?
⚠ Common exam trap
Many exam-takers confuse a standard FQDN object (which requires an exact match) with a Wildcard FQDN object (which supports pattern matching), leading them to incorrectly select option A when the question explicitly asks for a pattern like *.example.com.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Wildcard FQDN object
A Wildcard FQDN object (option B) is the correct choice because it allows pattern matching with a leading asterisk (e.g., *.example.com) to match any subdomain of example.com. Standard FQDN objects require an exact, fully qualified domain name and do not support wildcard patterns, making them unsuitable for matching traffic based on a domain pattern like *.example.com.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
FQDN object
Why it's wrong here
A standard FQDN object represents a single literal hostname, such as `mail.example.com`, and FortiGate resolves it to a specific IP address via DNS at policy evaluation time. It does not accept any wildcard characters, so it cannot match a base domain and all of its subdomains. Additionally, if the FQDN resolves to multiple IPs, the object still only applies to that exact name, not to sibling names under the same parent domain.
- ✓
Wildcard FQDN object
Why this is correct
A wildcard FQDN object is the correct object type because it supports pattern matching with an asterisk, for example `*.example.com`. This pattern matches both the apex domain and all of its subdomains in FortiGate policies, and the matching is performed against the hostname seen in the traffic, not against a single resolved IP address. It is ideal for allowing an entire domain family regardless of the underlying IP addresses.
- ✗
Subnet object
Why it's wrong here
A subnet object is purely an IP address range expressed in CIDR notation, such as `192.0.2.0/24` or a single host address with a `/32` mask. It cannot contain domain names, FQDNs, or wildcard patterns, so it is structurally incapable of matching `example.com` or any of its subdomains. This object type is used for network- or host-based IP matching only, not for name-based policy decisions.
- ✗
Geography object
Why it's wrong here
A geography object enables policy matching based on the country associated with a source or destination IP address, using geolocation databases. It does not inspect or match domain names in any form, so a hostname like `example.com` or its subdomains would not be recognized or filtered using this object type. The geographic match is independent of the fully qualified domain name and cannot express wildcard patterns.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.