NSE4 Firewall Policies and NAT Practice Question
A network administrator notices that traffic from the internal network (10.0.1.0/24) to the internet is not being matched by the intended firewall policy (ID 10). The policy uses source address 'internal_subnet' (10.0.1.0/24) and destination address 'all'. There is another policy (ID 5) with source 'all' and destination 'all' that also matches this traffic. What is the most likely reason policy 10 is not being matched?
⚠ Common exam trap
Candidates often think policy priority is based on specificity or configuration details like certificates or schedules, but FortiGate strictly uses sequential order from top to bottom, making the position of the 'all' policy the critical factor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policy 5 has a higher priority because it is above policy 10 in the policy list
FortiGate firewall policies are evaluated sequentially from top to bottom, and the first matching policy is applied. Since policy 5 with source 'all' and destination 'all' is listed above policy 10, traffic from 10.0.1.0/24 to the internet matches policy 5 first, preventing policy 10 from ever being evaluated. This is the most likely reason the intended policy is not being matched.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Policy 5 has a higher priority because it is above policy 10 in the policy list
Why this is correct
In Fortinet FortiGate, firewall policies are evaluated sequentially from top to bottom; the first matching policy is applied. Since Policy 5 is listed above Policy 10, and both match the same traffic (e.g., source internal_subnet, destination, service), FortiGate selects Policy 5 and stops evaluating further. Therefore, Policy 10 is never reached, making its order, not its settings, the cause of its non-execution.
- ✗
Policy 10 is configured with an expired security certificate
Why it's wrong here
Security certificates are used for SSL inspection, HTTPS decryption, or VPN authentication; they do not affect policy matching or evaluation order. A firewall policy is matched based on source/destination address, service, schedule, and interfaces, not on certificate validity. An expired certificate might cause SSL-related errors but would not prevent a policy from being selected when its other criteria match. Therefore, this is not the reason Policy 10 is bypassed.
- ✗
The source address object 'internal_subnet' is incorrectly configured
Why it's wrong here
If the source address object 'internal_subnet' were misconfigured, it would cause matching failures for all policies referencing it, including Policy 5 and Policy 10 alike. Since both policies use the same source object, the traffic from that subnet will match the criteria equally; the issue is not the object definition but the order in which the policies appear. Also, the scenario states the traffic is from internal_subnet, so the source object correctly identifies the traffic. Thus, this is not the cause.
- ✗
Policy 10 has a schedule that is not active
Why it's wrong here
FortiGate policy schedules restrict when a policy is active; if Policy 10's schedule were inactive at the moment of the traffic, the policy would not be considered for matching. However, the scenario does not mention any schedule configured on Policy 10, and the problem is that Policy 5, positioned above, already matches and terminates the evaluation. Even if Policy 10 had an active schedule, it would still be skipped because Policy 5 is matched first. Therefore, a schedule issue is not the reason.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.