Which statement about the implicit deny policy on a FortiGate is true?
This is the correct statement. In FortiOS, the implicit deny is always located at the very end of the policy list, after every user-created policy, and serves as the final catch-all rule. During sequential policy lookup, if no explicit policy matches the traffic parameters, the implicit deny matches all remaining sessions and blocks them by discarding the packets, thereby enforcing a strict default-deny posture.
Why this answer
The implicit deny policy is a built-in, non-configurable security policy that resides at the very bottom of the FortiGate policy list. It automatically denies all traffic that does not match any explicit user-defined policy, ensuring that only explicitly permitted traffic is allowed through the firewall.
Exam trap
The trap here is that candidates often think the implicit deny can be modified or moved, confusing it with a regular policy, but FortiGate enforces it as an unchangeable last-resort rule that cannot be deleted, reordered, or altered.
How to eliminate wrong answers
Option A is wrong because the implicit deny policy is not user-configurable and cannot be deleted; it is a hardcoded default rule. Option B is wrong because the implicit deny policy denies, not allows, traffic that matches no other policy. Option C is wrong because the implicit deny policy is fixed at the bottom of the policy list and cannot be moved to a different position.