Courseiva
Firewall Policies and NAT →mediumMultiple Choice

NSE4 Firewall Policies and NAT Practice Question

A network admin has configured a firewall policy allowing HTTPS traffic from the internal network to a DMZ web server. Users report that the web pages load slowly. The admin checks the policy and notices traffic shaping is not applied. What is the BEST action to ensure fair bandwidth distribution for HTTPS traffic?

⚠ Common exam trap

Candidates often confuse QoS (which prioritizes packets) with traffic shaping (which controls bandwidth allocation), leading them to select option D, but QoS alone does not enforce fair distribution of bandwidth across multiple sessions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a traffic shaping policy and apply it to the firewall policy

Traffic shaping is the correct mechanism to enforce fair bandwidth distribution for HTTPS traffic. By creating a traffic shaping policy and applying it to the firewall policy, the admin can allocate a specific bandwidth guarantee or limit for HTTPS sessions, preventing them from starving other traffic. Without shaping, HTTPS traffic can consume all available bandwidth, causing slow performance for other users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a traffic shaping policy and apply it to the firewall policy

    Why this is correct

    In FortiGate, bandwidth control is enforced through traffic shaping policies that are directly referenced by a firewall policy. You can assign a shared or per-IP traffic shaper with guaranteed and maximum bandwidth values, plus a priority level, so matching HTTPS sessions get explicit bandwidth limits and fair distribution. This is the only option that applies per-policy rate limiting, allowing the administrator to cap and prioritize traffic without affecting other policies.

  • ✗

    Increase the bandwidth of the internet link

    Why it's wrong here

    Increasing the bandwidth of the internet link only adds more capacity; it does not allocate or shape traffic between different service types. Unless per-policy shapers are in place, bulk transfers or heavy downloads can still consume all available bandwidth, making HTTPS and interactive traffic suffer. This approach treats the symptom (congestion) rather than the root cause (lack of fair distribution), and it does not guarantee any bandwidth for critical applications.

  • ✗

    Configure policy-based routing for HTTPS traffic

    Why it's wrong here

    Policy-based routing (PBR) changes the forwarding path or next hop for selected traffic based on source, destination, or other attributes. It does not apply rate limits or modify bandwidth allocations; even if HTTPS is sent via a different route, it can still experience the same congestion on the outbound interface. PBR is for path selection and load balancing, not for controlling how much bandwidth a policy can consume.

  • ✗

    Enable QoS on the outgoing interface

    Why it's wrong here

    Enabling QoS on the outgoing interface configures egress bandwidth settings and priorities, but it only provides class-based queuing and prioritization without applying per-policy committed or maximum bandwidth limits. While it can give HTTPS a higher priority, it does not cap or guarantee throughput for specific firewall policies, so lower-priority bulk traffic can still consume the remaining bandwidth and potentially starve other classes. Interface QoS also only operates at the interface level, lacking the granularity to enforce traffic shaping policy per match in a firewall rule.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.