NSE4 Firewall Policies and NAT Practice Question
An admin configures a firewall policy with a schedule object that restricts access to Monday to Friday from 9:00 to 17:00. A user attempts to connect on Saturday at 10:00. Which of the following best describes what happens?
⚠ Common exam trap
NSE4 often tests the behavior of schedules in firewall policies, and candidates may incorrectly think that the schedule itself denies traffic or that the policy is still evaluated but with a different action, rather than being skipped entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The FortiGate skips this policy and tries the next policy; if no match, implicit deny blocks the traffic
When a firewall policy includes a schedule, the policy is only active during the specified time. Outside that schedule, the policy is skipped entirely, and the FortiGate evaluates the next policy in the list. If no subsequent policy matches, the implicit deny rule at the end blocks the traffic. Therefore, on Saturday at 10:00, the policy is skipped, and if no other policy allows it, the traffic is denied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The traffic is allowed because the schedule is only used for logging
Why it's wrong here
A schedule object in FortiGate is a time-based match condition that controls policy enforcement, not merely a logging attribute. When the current time falls outside the schedule's range, the policy does not match, and the FortiGate continues to the next policy. Therefore, the traffic is not allowed by this policy; it would be dropped by implicit deny if no other policy matches.
- ✗
The traffic is allowed because the schedule is optional
Why it's wrong here
In FortiGate, a schedule is a mandatory attribute of every firewall policy; the default is the 'always' schedule, but when an administrator binds a specific schedule, that schedule must match for the policy to be considered. Calling it optional is misleading because the schedule is evaluated on every packet, and a non-matching schedule causes the policy to be bypassed entirely. Thus, traffic is not allowed simply because the schedule field exists in the policy.
- ✓
The FortiGate skips this policy and tries the next policy; if no match, implicit deny blocks the traffic
Why this is correct
During firewall policy lookup, the FortiGate checks all match criteria in sequence per policy, including the schedule. If the current time does not fall within the configured schedule for a policy, that policy is skipped and evaluation proceeds to the next policy with its own schedule and other conditions. If no subsequent policy matches, the packet is dropped by the implicit deny rule, which is the default drop-all behavior at the end of the policy table.
- ✗
The traffic is denied because the schedule is not valid
Why it's wrong here
The schedule object is not invalid; it is a properly configured object whose time range simply does not include the current time. FortiGate does not generate an error or treat this as a configuration fault; instead, it treats the schedule as a non-matching policy attribute, causing the policy to be skipped during evaluation. Consequently, the traffic is not denied by this policy — it may be denied later by implicit deny only if no other policy matches.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.