Courseiva

NSE4 Firewall Policies and NAT Practice Question

A FortiGate policy allows traffic from the internal network to a DMZ server. The admin wants to limit access to only specific hours. Which object type should be used in the policy?

⚠ Common exam trap

Many candidates confuse a schedule with a service group, thinking they can restrict time by limiting port availability, but FortiGate requires a dedicated schedule object for time-based policy enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Schedule

A schedule object is the correct choice because it defines time-based conditions (e.g., specific hours, days, or recurring intervals) that FortiGate applies to firewall policies. By attaching a schedule to a policy, the admin can restrict traffic to the DMZ server only during the permitted hours, such as business hours or maintenance windows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Address group

    Why it's wrong here

    Address group is incorrect because a FortiGate address group aggregates IP address objects (such as subnets or FQDNs) used for matching the source and destination fields in a firewall policy, not the temporal validity of the rule. Time-based access is controlled solely by the schedule field, which is a separate object type. Even if an address group's members are updated dynamically, it cannot restrict when traffic is allowed—only from where.

  • ✓

    Schedule

    Why this is correct

    Schedule is correct because FortiGate uses schedule objects (one-time or recurring) to define when a policy is permitted to match traffic. The policy's schedule field is evaluated during the lookup process; if the current time is outside the defined start/end and day-of-week parameters, the policy is skipped and traffic is compared against subsequent rules. This provides precise control over business hours, maintenance windows, or one-off events.

  • ✗

    Service group

    Why it's wrong here

    Service group is wrong because it is a collection of service objects that define protocols and port numbers (e.g., TCP/443 or UDP/53) for matching the service field in a policy, not the time of day. A service group narrows the type of traffic, but the schedule field independently governs when the policy is active. Without a schedule, a policy is effectively always enabled, regardless of which service group is referenced.

  • ✗

    Traffic shaper

    Why it's wrong here

    Traffic shaper is incorrect because traffic shapers (shared or per-IP) are applied to a matched policy to enforce bandwidth limits and prioritization, such as guaranteeing throughput or setting max bandwidth. They do not constrain the time window in which a policy can match traffic. A policy with a traffic shaper will still match at any time unless a schedule object is explicitly configured—shaping only comes into play after the policy is selected.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.