Courseiva
Firewall Policies and NAT →mediumMultiple Choice

NSE4 Firewall Policies and NAT Practice Question

An admin creates a firewall policy allowing HTTP traffic from internal users to the internet. Users complain that they cannot access HTTPS websites. The admin checks and sees that the policy only has HTTP service. What is the BEST course of action to allow HTTPS while maintaining security?

⚠ Common exam trap

Many candidates think creating a new policy above the existing one is necessary for ordering, but FortiGate allows multiple services in a single policy, making modification the best practice for simplicity and security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the HTTPS service to the existing policy

Adding the HTTPS service (TCP/443) to the existing policy allows HTTPS traffic without creating a separate rule, which could introduce complexity or misordering issues. This approach maintains security by explicitly permitting only the required service rather than opening all traffic. FortiGate policies evaluate services as part of the match criteria, so modifying the existing policy is the most efficient and secure method.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a new policy above the existing one with HTTPS service

    Why it's wrong here

    Creating a new policy above the existing one for HTTPS traffic is not the best approach as it leads to policy duplication and increased management overhead. The existing policy already permits internal users to the internet for HTTP, and simply needs to be amended to include HTTPS service alongside HTTP. This option is tempting because creating policies higher in the list is correct when specific traffic requires different security profiles, logging, or NAT settings than what a broader, lower-priority policy would apply, or to create an explicit exception.

  • ✓

    Add the HTTPS service to the existing policy

    Why this is correct

    Adding the HTTPS service object to the existing policy is the correct and most efficient approach. The policy already matches the desired source (internal users) and destination (internet) with a permit action for HTTP; extending the service list to include HTTPS (port 443/tcp) requires no change to the other match criteria or security profiles. This preserves least privilege by allowing only the specific web protocols intended, while avoiding policy duplication and administrative overhead. FortiGate security policies allow multiple service objects, so HTTP and HTTPS can coexist cleanly in the same rule.

  • ✗

    Use a security policy that automatically adds HTTPS

    Why it's wrong here

    FortiGate does not offer any 'security policy that automatically adds HTTPS' — this is not a real feature. Security policies in FortiOS are explicit: the service field must contain concrete service objects or groups (e.g., HTTP, HTTPS, ALL), and there is no dynamic mechanism that self-updates the policy based on observed traffic types. Application control or SSL inspection may *see* HTTPS traffic, but neither can modify the policy's allowed service list. Therefore, this option reflects a misunderstanding of how FortiGate evaluates and enforces policies.

  • ✗

    Change the HTTP service to ALL services

    Why it's wrong here

    Changing the HTTP service to the ALL service object would make the policy permit every protocol and port (TCP/UDP/SCTP, all numbers) between the matched source and destination. This is far too permissive and violates the principle of least privilege, unnecessarily exposing internal users to protocols such as SSH, Telnet, SMTP, and any custom services. While HTTPS would indeed be allowed, the policy would also allow all other traffic, turning the firewall into a wide-open conduit and greatly increasing the attack surface. The right fix is to add HTTPS explicitly, not to broaden the service mask to everything.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.