NSE4 Firewall Policies and NAT Practice Question
A FortiGate policy allows traffic from the internal network to a DMZ server. The admin wants to limit access to only specific hours. Which object type should be used in the policy?
⚠ Common exam trap
Many candidates confuse a schedule with a service group, thinking they can restrict time by limiting port availability, but FortiGate requires a dedicated schedule object for time-based policy enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Schedule
A schedule object is the correct choice because it defines time-based conditions (e.g., specific hours, days, or recurring intervals) that FortiGate applies to firewall policies. By attaching a schedule to a policy, the admin can restrict traffic to the DMZ server only during the permitted hours, such as business hours or maintenance windows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Address group
Why it's wrong here
Address group is incorrect because a FortiGate address group aggregates IP address objects (such as subnets or FQDNs) used for matching the source and destination fields in a firewall policy, not the temporal validity of the rule. Time-based access is controlled solely by the schedule field, which is a separate object type. Even if an address group's members are updated dynamically, it cannot restrict when traffic is allowed—only from where.
- ✓
Schedule
Why this is correct
Schedule is correct because FortiGate uses schedule objects (one-time or recurring) to define when a policy is permitted to match traffic. The policy's schedule field is evaluated during the lookup process; if the current time is outside the defined start/end and day-of-week parameters, the policy is skipped and traffic is compared against subsequent rules. This provides precise control over business hours, maintenance windows, or one-off events.
- ✗
Service group
Why it's wrong here
Service group is wrong because it is a collection of service objects that define protocols and port numbers (e.g., TCP/443 or UDP/53) for matching the service field in a policy, not the time of day. A service group narrows the type of traffic, but the schedule field independently governs when the policy is active. Without a schedule, a policy is effectively always enabled, regardless of which service group is referenced.
- ✗
Traffic shaper
Why it's wrong here
Traffic shaper is incorrect because traffic shapers (shared or per-IP) are applied to a matched policy to enforce bandwidth limits and prioritization, such as guaranteeing throughput or setting max bandwidth. They do not constrain the time window in which a policy can match traffic. A policy with a traffic shaper will still match at any time unless a schedule object is explicitly configured—shaping only comes into play after the policy is selected.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.