NSE4 Firewall Policies and NAT Practice Question
An admin notices that a firewall policy allowing inbound HTTPS to a server is not matching traffic. The policy has source set to 'all', destination to the server's IP, and service to HTTPS. The admin checks the policy list and sees that policy ID 1 matches the traffic. What is the MOST likely reason the intended policy (ID 10) is not matching?
⚠ Common exam trap
It's easy for candidates to think policy ID numbers determine priority, but FortiGate uses the sequential order in the policy list, not the ID number, and the default policy ID 1 is often an 'allow all' or 'deny all' rule that matches before any lower-ID policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policy ID 1 has a higher priority and matches before policy ID 10
Policy ID 1 has a higher priority because FortiGate evaluates firewall policies in sequential order from top to bottom. When policy ID 1 matches the traffic (e.g., it also allows HTTPS to the same destination), the traffic is processed by policy ID 1 and never reaches policy ID 10. This is the most likely reason the intended policy is not matching.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Policy ID 1 has a higher priority and matches before policy ID 10
Why this is correct
FortiGate security policies are evaluated sequentially from the top of the policy table, and the first policy that matches all criteria (source, destination, service, schedule, etc.) is applied, terminating the lookup. Policy ID 1 has a lower numeric ID, which places it above policy ID 10 in the default ordering, so it is evaluated first. Because policy ID 1 already matches the inbound traffic, policy ID 10 is never reached, even if its configuration is perfectly valid. This is a classic policy shadowing issue where a broader or earlier policy overrides a more specific later one.
- ✗
The firewall policy is disabled
Why it's wrong here
If the firewall policy were disabled, it would be visually marked as disabled in the GUI or show 'disable' in the CLI configuration, and it would be completely excluded from the policy lookup process. However, the question describes a policy that is present and likely enabled but ineffective, which points to a matching/ordering problem rather than a disabled state. Even if policy ID 10 were enabled, it cannot influence traffic that already matched and was acted upon by policy ID 1. The admin would need to check the policy's enabled status, but the root cause here is not the disabled state but the evaluation order.
- ✗
The service object for HTTPS is misconfigured in policy ID 10
Why it's wrong here
A misconfigured HTTPS service object in policy ID 10 could cause that policy to fail to match inbound HTTPS traffic, but that would only matter if the traffic actually reached policy ID 10 for evaluation. In this scenario, policy ID 1 matches the traffic first and is applied, so the service object in policy ID 10 is never examined. Even if the service object were corrected, the traffic would still match policy ID 1 and policy ID 10 would continue to be bypassed. Thus, the misconfiguration is irrelevant to the current symptom because the policy is shadowed by a higher-priority rule.
- ✗
The destination address is incorrect in policy ID 10
Why it's wrong here
An incorrect destination address in policy ID 10 would prevent it from matching the intended traffic, but this issue would only be observed if the traffic were evaluated against policy ID 10. Since policy ID 1 is evaluated first and matches the incoming HTTP session, policy ID 10 is never reached, regardless of whether its destination address is correct or not. Even if the destination address were corrected, policy ID 10 would still not get a chance to handle the traffic because the lookup already terminated at policy ID 1. Therefore, the destination address misconfiguration is not the cause of the admin's observation; the ordering is the true culprit.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.