NSE4 Firewall Policies and NAT Practice Question
A FortiGate administrator wants to restrict access to a sensitive server (10.0.0.100) such that only users who authenticate via LDAP can access it. Which firewall policy configuration is required?
⚠ Common exam trap
Test-takers frequently think enabling authentication alone is sufficient, but they overlook the critical need to specify a group to restrict access to only the intended subset of authenticated users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policy: source any, destination 10.0.0.100, service any, action accept, enable authentication, set auth-type LDAP, set groups "LDAP-Users"
It combines the required firewall policy elements: enabling authentication, setting the authentication type to LDAP, and restricting access to members of the LDAP group 'LDAP-Users'. This ensures that only users who successfully authenticate via LDAP and belong to the specified group can reach the sensitive server at 10.0.0.100. Without the group restriction, any authenticated LDAP user could access the server, which does not meet the requirement of restricting access to only authenticated users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Policy: source any, destination 10.0.0.100, service any, action accept
Why it's wrong here
This policy simply permits all traffic to 10.0.0.100 without any identity check. Since authentication is not enabled, FortiGate will not prompt for credentials or check group membership, so any user—authenticated or not—can reach the sensitive destination. Restricting access requires enabling authentication and binding the policy to a specific LDAP user group.
- ✗
Policy: source any, destination 10.0.0.100, service any, action accept, enable authentication, set auth-type LDAP
Why it's wrong here
Although authentication is enabled and set to LDAP, the policy lacks a group reference, making it incomplete in FortiOS. For identity-based policies, the firewall requires at least one user group to evaluate authorization; without it, the policy cannot determine which users are allowed and will not enforce LDAP-based restrictions. You must specify an LDAP group, such as 'LDAP-Users', to complete the configuration.
- ✓
Policy: source any, destination 10.0.0.100, service any, action accept, enable authentication, set auth-type LDAP, set groups "LDAP-Users"
Why this is correct
This is the correct configuration because it enables authentication, selects LDAP as the authentication type, and explicitly restricts access to members of the LDAP-Users group. In FortiOS, an identity-based policy with a specified group enforces both authentication (credentials verified against LDAP) and authorization (group membership checked). After a user authenticates successfully and is a member of LDAP-Users, the accept action permits traffic to 10.0.0.100.
- ✗
Policy: source any, destination 10.0.0.100, service any, action accept, enable FSSO authentication
Why it's wrong here
FSSO relies on a different mechanism—collecting domain logon events from Windows servers—rather than forcing LDAP authentication at the firewall. Enabling FSSO on this policy does not verify credentials against LDAP nor does it specify a group like 'LDAP-Users', so it fails to fulfill the requirement for LDAP-based access restriction. Additionally, FSSO is typically used for transparent single sign-on and doesn't provide the same per-policy authentication with a defined group.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.