NSE4 Firewall Policies and NAT Practice Question
A network administrator needs to allow only HTTPS traffic from the internal network (10.0.0.0/8) to the public DNS server (8.8.8.8). Which firewall policy configuration BEST enforces this restriction?
⚠ Common exam trap
Candidates often confuse 'service' with 'destination port' and overlook that specifying 'ALL' for service or destination will permit unintended traffic, failing the precise restriction required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Source: 10.0.0.0/8, Destination: 8.8.8.8, Service: HTTPS, Action: Accept
It specifies the internal network (10.0.0.0/8) as the source, the public DNS server (8.8.8.8) as the destination, and HTTPS (TCP/443) as the service, with an Accept action. This precisely matches the requirement to allow only HTTPS traffic from the internal network to that specific destination, blocking all other traffic by default via the implicit deny rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Source: ALL, Destination: 8.8.8.8, Service: HTTPS, Action: Accept
Why it's wrong here
This rule is incorrect because the source is defined as ALL, meaning any host on any interface or network can initiate HTTPS traffic to 8.8.8.8. The stated requirement restricts the source to the internal 10.0.0.0/8 subnet, so this policy violates the principle of least privilege by exposing the destination to external or unapproved sources. A FortiGate policy must constrain the source to the specific internal range to enforce the intended segmentation.
- ✗
Source: 10.0.0.0/8, Destination: 8.8.8.8, Service: ALL, Action: Accept
Why it's wrong here
This rule fails because Service is set to ALL, which permits every protocol and port (e.g., SSH, Telnet, SMTP, or arbitrary UDP) between the 10.0.0.0/8 network and 8.8.8.8. The requirement is to allow only HTTPS (TCP/443), so the service object must be HTTPS, not ALL. Overly broad service definitions can create bypass or lateral movement paths and should be tightened to the minimum necessary ports.
- ✓
Source: 10.0.0.0/8, Destination: 8.8.8.8, Service: HTTPS, Action: Accept
Why this is correct
This rule is correct because it precisely matches the three constraints: the internal source subnet 10.0.0.0/8, the specific destination IP 8.8.8.8, and the well-known HTTPS service (TCP/443). FortiGate evaluates the source address, destination address, and service object together; when all three match, the Accept action permits the traffic. This adheres to least privilege and aligns directly with the stated requirement.
- ✗
Source: 10.0.0.0/8, Destination: ALL, Service: HTTPS, Action: Accept
Why it's wrong here
This rule is wrong because the destination address is ALL, allowing HTTPS connections to any destination IP, not just 8.8.8.8. The scenario specifies that only traffic to 8.8.8.8 should be allowed; a broad destination means users could reach arbitrary public websites over HTTPS, defeating the purpose of restricting to a single host. The destination must be narrowed to the exact IP address.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.