NSE4 Firewall Policies and NAT Practice Question
A junior admin is creating firewall policies and wants to ensure that all traffic not explicitly permitted is denied. Which FortiGate mechanism provides this behavior by default?
⚠ Common exam trap
It's easy for candidates to think the last explicit deny policy (Option C) is the default mechanism, but FortiGate's implicit deny rule is always present and active by default, whereas an explicit deny policy must be manually added and is not a default behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The implicit deny rule
The implicit deny rule is a default, hidden policy at the end of the FortiGate firewall policy list that denies all traffic not explicitly permitted by any user-created policy. This behavior is inherent to the FortiGate operating system and ensures a default-deny posture without requiring manual configuration. It is always present and cannot be deleted or moved, providing a safety net that blocks any unmatched traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The security profile group
Why it's wrong here
Security profile groups apply intrusion prevention, antivirus, web filtering, and other UTM inspection to traffic that has already been permitted by a firewall policy. They never create an implicit or explicit deny condition; if a policy is too permissive, the security profile can only block specific threats, not unapproved traffic. Thus, relying on a security profile group cannot enforce a default-deny posture because it does not evaluate whether the session should exist in the first place.
- ✗
The default route
Why it's wrong here
The default route is a routing table entry used to forward packets whose destination subnet is not explicitly known to the FortiGate. It has no bearing on firewall policy evaluation; even with a default route pointing to an ISP, the FortiGate still consults the policy list to decide whether to allow or deny the session. A default route does not filter or drop traffic, so it cannot act as a final deny mechanism for traffic that matches no explicit allow policy.
- ✗
The last explicit deny policy in the policy list
Why it's wrong here
The last explicit deny policy is sometimes added by administrators to log or explicitly drop unmatched traffic, but it is not mandatory for default-deny behavior. If an administrator removes or misorders that policy, traffic that fails to match any allow rule may fall through to the implicit deny, which is always present at the end of the policy list. Therefore, the implicit deny—not the last explicit deny—is the actual guarantee that unapproved traffic is dropped, making the explicit deny an optional aid for logging rather than the core enforcement mechanism.
- ✓
The implicit deny rule
Why this is correct
The implicit deny rule is a built-in, invisible final policy on every FortiGate firewall; any session that does not match an explicit allow or explicit deny policy is automatically dropped and logged. This rule cannot be deleted or disabled, ensuring that the firewall always enforces a default-deny posture for all unpermitted traffic. It is the true answer to the question because it is automatically applied, requiring no configuration, and it closes the gap that would otherwise allow traffic to pass unchecked.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 282-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.