Courseiva

NSE4 Firewall Policies and NAT Practice Question

A FortiGate is configured with multiple policies. The first policy allows traffic from 10.0.0.0/8 to any destination. The second policy denies traffic from 10.0.1.0/24 to any destination. What happens when a packet from 10.0.1.5 to 8.8.8.8 arrives?

⚠ Common exam trap

Test-takers frequently assume FortiGate uses a longest-prefix match or that a more specific deny policy will override a broader allow policy, but FortiGate strictly follows first-match order, not prefix length.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The packet is allowed by the first policy

FortiGate firewall policies are evaluated in sequential order from top to bottom. The first policy matches source 10.0.0.0/8, which includes 10.0.1.5, and allows the traffic to any destination. Since the packet matches this policy first, it is accepted and the second policy is never evaluated. Therefore, the packet is allowed by the first policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The packet is denied by implicit deny

    Why it's wrong here

    The implicit deny is the final default action in FortiGate's policy list and only triggers when no explicit policy matches the traffic. In this case, the first explicit policy matches the source 10.0.1.5 because it falls within the 10.0.0.0/8 subnet, and the policy's action is allow. Therefore, the packet is forwarded before the policy lookup ever reaches the implicit deny, which is not a competing rule but a fallback safeguard that is ignored when an earlier match occurs.

  • ✓

    The packet is allowed by the first policy

    Why this is correct

    The first policy's source address range of 10.0.0.0/8 encompasses the packet's source IP 10.0.1.5, and if the other matching criteria (destination, service, incoming/outgoing interface) also align, FortiGate applies that policy's allow action. Policy evaluation is sequential and stops at the first match, so the allow decision is executed immediately. This makes the first policy the definitive rule that governs this traffic, regardless of what later policies define.

  • ✗

    The packet matches both policies and is allowed

    Why it's wrong here

    FortiGate does not aggregate or evaluate all matching policies; it selects exactly one policy—the first one that matches—and applies only that policy's action. Even if the second policy's source range also covers 10.0.1.5, it is never considered because the lookup terminates as soon as the first policy matches. Therefore, the traffic is allowed solely due to the first policy's allow action, not because multiple policies all permit it, and the second policy has no influence on this packet.

  • ✗

    The packet is denied by the second policy

    Why it's wrong here

    The second policy is never reached in the policy lookup because the first policy already matched the packet and allowed it. FortiGate's ordered rule evaluation is top-down and stops at the first matching rule, so the deny action in the second policy is irrelevant for this traffic. The second policy would only take effect if the first policy did not match, for example if the source IP were outside the 10.0.0.0/8 range, which is not the case here.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.