Courseiva
Firewall Policies and NAT →mediumMultiple Choice

NSE4 Firewall Policies and NAT Practice Question

An admin wants to apply different QoS markings to traffic from two different departments. The admin creates two firewall policies: one for Sales (policy ID 1) and one for Engineering (policy ID 2). Both policies have traffic shaping enabled. However, traffic from both departments receives the same QoS marking. What is the MOST likely mistake?

⚠ Common exam trap

It's easy for candidates to assume creating separate firewall policies automatically results in different QoS markings, but they overlook that the traffic shaper itself must be unique and configured with the correct DSCP value for each policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The admin applied the same traffic shaper to both policies

If the same traffic shaper is applied to both firewall policies, the QoS marking defined in that shaper will be identical for all matched traffic, regardless of the policy. Each policy must reference a distinct traffic shaper with the desired DSCP or 802.1p marking to differentiate the departments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The policies are in the wrong order

    Why it's wrong here

    In FortiGate, firewall policies are matched from top to bottom, so policy order can affect which policy handles a session when multiple policies match the same traffic. However, since these policies were intended for different subnets or traffic types, each session matches only its own intended policy regardless of their order. Swapping the two policies would not change the fact that both reference the same traffic shaper object, so the QoS marking would remain identical. Reordering is only a meaningful fix when the policies' match criteria overlap and the wrong rule is being hit first.

  • ✗

    QoS marking is only applied at the interface level

    Why it's wrong here

    FortiOS does not restrict QoS or diffserv marking to the physical or VLAN interface configuration. A firewall policy can independently assign a traffic shaper, a per-IP shaper, and can set or override diffserv/ToS values for matching sessions. Interface-level QoS settings and per-policy traffic shaping are separate mechanisms and can coexist, so the administrator is not limited to interface configuration. The real problem is not where QoS is applied, but that the same shaper object was attached to both policies, preventing distinct markings.

  • ✗

    The traffic shaping policy is applied globally

    Why it's wrong here

    If a traffic shaping policy were truly applied globally, it would affect all traffic flows uniformly, which is not what the administrator configured here. FortiGate's firewall-policy traffic shapers are attached to individual policies and are evaluated per session, even though the same shaper object can be reused across multiple rules. Global QoS settings establish system-wide defaults or interface parameters, but they do not stop an administrator from assigning different per-policy shapers. The actual cause is that the same shaper object is explicitly referenced by both policy rules, making the shaping identical rather than global.

  • ✓

    The admin applied the same traffic shaper to both policies

    Why this is correct

    When both firewall policies reference the identical traffic-shaper object, the QoS markings and bandwidth parameters applied by that shaper are the same for every matching session. To apply different QoS markings, the administrator must create at least two distinct traffic shapers, or configure separate diffserv/ToS values, and attach the appropriate shaper to each policy. If the shaper is the same in both rules, no amount of policy reordering or interface tweaking will produce separate markings. The correct solution is to give each traffic class its own shaper object so bandwidth allocation and diffserv markings can differ.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.