Courseiva
Firewall Policies and NAT →mediumMultiple Choice

NSE4 Firewall Policies and NAT Practice Question

A FortiGate has two policies for traffic from port1 to port3: Policy 1 (destination 10.0.1.0/24, schedule always, action accept) and Policy 2 (destination 10.0.2.0/24, schedule 'Weekdays', action accept). A packet destined to 10.0.2.10 arrives on Wednesday at 2 PM. Which policy is applied?

⚠ Common exam trap

Watch out — candidates often assume policy order alone determines matching (Option D), but they overlook that the destination must match first, and schedules must be active for the policy to be considered.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Policy 2 because it matches the destination and the schedule is active

Policy 2 is applied because it matches the destination IP (10.0.2.10) and the schedule 'Weekdays' is active on Wednesday at 2 PM. FortiGate uses a first-match approach only when multiple policies have the same priority; here, Policy 1 does not match the destination, so Policy 2 is the only matching policy. Since the schedule is valid, the action 'accept' is executed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Policy 2 because it matches the destination and the schedule is active

    Why this is correct

    Policy 2 is the effective policy because FortiGate selects the first policy from the top that matches ALL required criteria: source interface/address, destination interface/address, service, and schedule. Policy 1 does not match the destination (its destination does not include port3 or the target IP), so it is skipped. Policy 2 matches the destination and its schedule is currently active, so it both matches and is the first matching policy; therefore traffic is permitted. In FortiGate's sequential top-down evaluation, only the first full match is used.

  • ✗

    Both policies are applied sequentially

    Why it's wrong here

    Firewall policies in FortiGate are not chained or summed; a single session is bound to exactly one policy on its first packet. Once the session table entry is created, all subsequent packets of that flow are processed against that session's policy only, not re-evaluated against other policies. Therefore 'both policies are applied sequentially' is incorrect: Policy 2 alone authorizes and handles the traffic, and Policy 1's rules have no effect on this connection.

  • ✗

    Neither; the implicit deny applies

    Why it's wrong here

    The implicit deny rule exists at the very end of the policy table and drops any traffic that matches no explicit policy. Because Policy 2 explicitly matches this traffic's source, destination, service, and a currently valid schedule, the session is allowed and never reaches the implicit deny. So the traffic does not hit the deny-all tail; the explicit permit takes precedence.

  • ✗

    Policy 1 because it is listed first

    Why it's wrong here

    Although FortiGate does evaluate policies in order from top to bottom, the position of Policy 1 does not matter if it fails to match the traffic. Policy 1's configured destination does not include the port3 destination (or the specific destination object) used by this session, so it is not a candidate. Evaluation then continues to Policy 2, which matches, so claiming Policy 1 'because it is listed first' conflates list order with actual field matching — a non-matching policy is never selected.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.