NSE4 Firewall Policies and NAT Practice Question
A FortiGate is configured with multiple policies. The first policy allows traffic from 10.0.0.0/8 to any destination. The second policy denies traffic from 10.0.1.0/24 to any destination. What happens when a packet from 10.0.1.5 to 8.8.8.8 arrives?
⚠ Common exam trap
Test-takers frequently assume FortiGate uses a longest-prefix match or that a more specific deny policy will override a broader allow policy, but FortiGate strictly follows first-match order, not prefix length.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The packet is allowed by the first policy
FortiGate firewall policies are evaluated in sequential order from top to bottom. The first policy matches source 10.0.0.0/8, which includes 10.0.1.5, and allows the traffic to any destination. Since the packet matches this policy first, it is accepted and the second policy is never evaluated. Therefore, the packet is allowed by the first policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The packet is denied by implicit deny
Why it's wrong here
The implicit deny is the final default action in FortiGate's policy list and only triggers when no explicit policy matches the traffic. In this case, the first explicit policy matches the source 10.0.1.5 because it falls within the 10.0.0.0/8 subnet, and the policy's action is allow. Therefore, the packet is forwarded before the policy lookup ever reaches the implicit deny, which is not a competing rule but a fallback safeguard that is ignored when an earlier match occurs.
- ✓
The packet is allowed by the first policy
Why this is correct
The first policy's source address range of 10.0.0.0/8 encompasses the packet's source IP 10.0.1.5, and if the other matching criteria (destination, service, incoming/outgoing interface) also align, FortiGate applies that policy's allow action. Policy evaluation is sequential and stops at the first match, so the allow decision is executed immediately. This makes the first policy the definitive rule that governs this traffic, regardless of what later policies define.
- ✗
The packet matches both policies and is allowed
Why it's wrong here
FortiGate does not aggregate or evaluate all matching policies; it selects exactly one policy—the first one that matches—and applies only that policy's action. Even if the second policy's source range also covers 10.0.1.5, it is never considered because the lookup terminates as soon as the first policy matches. Therefore, the traffic is allowed solely due to the first policy's allow action, not because multiple policies all permit it, and the second policy has no influence on this packet.
- ✗
The packet is denied by the second policy
Why it's wrong here
The second policy is never reached in the policy lookup because the first policy already matched the packet and allowed it. FortiGate's ordered rule evaluation is top-down and stops at the first matching rule, so the deny action in the second policy is irrelevant for this traffic. The second policy would only take effect if the first policy did not match, for example if the source IP were outside the 10.0.0.0/8 range, which is not the case here.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.