Courseiva
Firewall Policies and NAT →mediumMultiple Choice

NSE4 Firewall Policies and NAT Practice Question

A network admin configures a firewall policy allowing HTTP traffic from internal users to an external web server. The policy uses a service object 'HTTP' defined as TCP/80. However, users cannot reach the server. What is the MOST likely cause?

⚠ Common exam trap

Test-takers frequently assume HTTP traffic is always on port 80, but the question deliberately sets up a scenario where the server uses HTTPS (port 443), testing the understanding that firewall policies are port-specific and service objects must match the actual application protocol.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The external web server is using HTTPS (TCP/443) instead of HTTP

The firewall policy explicitly allows TCP/80 (HTTP), but the external web server is using TCP/443 (HTTPS). Since the service object does not match the actual traffic, the firewall will drop or reject the packets, preventing connectivity. This is a classic service mismatch issue in FortiGate firewall policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The external web server is using HTTPS (TCP/443) instead of HTTP

    Why this is correct

    The service object in this policy explicitly allows only TCP port 80 (HTTP). An external web server listening on TCP/443 (HTTPS) will not match this policy; FortiGate implicitly denies all traffic that does not match any explicit policy, so the client's HTTPS request is silently dropped. To permit the traffic, the admin must either change the service object to HTTPS (TCP/443) or create a separate policy with the correct service.

  • ✗

    The source address object does not include the users' subnet

    Why it's wrong here

    If the source address object is missing the users' subnet, the policy will not match any traffic originating from that subnet, causing those users to be blocked. However, this is a broader reachability issue and would likely affect all services from that subnet, not just HTTP vs HTTPS. The scenario specifically indicates an HTTP policy, so the more targeted cause is a service mismatch, not a source exclusion.

  • ✗

    The policy order is wrong; the policy is placed after a deny-all policy

    Why it's wrong here

    FortiGate evaluates policies in order and stops at the first match; a deny-all policy placed above this HTTP policy would preempt it and deny all HTTP traffic. While this is a valid misconfiguration, the symptom would be complete denial for the entire HTTP service, and the policy would show no hits. In contrast, a service mismatch (TCP/80 vs TCP/443) produces a more subtle problem where the policy appears correct but the server never responds to the expected port.

  • ✗

    The interface is set to the wrong zone

    Why it's wrong here

    Assigning the incoming interface to the wrong zone means this policy, which references a specific zone, will never be evaluated for traffic arriving on that interface. This misconfiguration would cause the policy to be silently bypassed, similar to a source error. However, interface zone misassignments are typically identified during initial setup, and the question's focus on HTTP service makes the service object mismatch a more likely and precise root cause.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.