NSE4 Firewall Policies and NAT Practice Question
An admin wants to block traffic from a specific geographic region (e.g., North Korea) from reaching the FortiGate's external interface. Which address object type should be used in the firewall policy?
⚠ Common exam trap
Test-takers frequently confuse geography address objects with subnet or FQDN objects, thinking they can manually list IP ranges for a country, but FortiGate requires the use of the built-in GeoIP database for country-based filtering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Geography address object
A geography address object allows the firewall to match traffic based on the source or destination IP address's registered country. FortiGate uses a built-in GeoIP database to map IP addresses to geographic regions, making it the correct choice for blocking traffic from a specific country like North Korea.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Subnet address object
Why it's wrong here
Subnet address objects in FortiOS define a fixed IP range using a network address and prefix length (e.g., 192.0.2.0/24) or explicit start/end addresses. Because they require manual, static input of every IP range, they cannot dynamically reflect the constantly changing IP allocations for an entire country or region. Blocking a specific geography by subnet would be impractical and incomplete, so this object type is the wrong choice.
- ✓
Geography address object
Why this is correct
A geography address object in FortiOS matches traffic based on the country or region mapped to the source or destination IP address, using the FortiGuard GeoIP database. When you add it to a firewall policy as the source address and set the action to DENY, all traffic originating from that geopolitical area is blocked dynamically, with no need to track individual IP ranges. This is the correct object type because it directly maps IP addresses to geographic locations.
- ✗
FQDN address object
Why it's wrong here
An FQDN address object resolves a fully qualified domain name, such as www.example.com, to its current IP address(es) and then uses those resolved addresses for policy matching. It cannot represent the entire IP space attributed to a country; instead it matches only the specific hostname's addresses, making it useful for domain-based control but not for geography-based blocking. Therefore, it is not suitable for blocking traffic from a geographic region.
- ✗
Wildcard FQDN address object
Why it's wrong here
A wildcard FQDN address object matches domain names and their subdomains using wildcard patterns, such as *.example.com, without any relation to IP address geolocation. This object type operates purely at the domain-name level, evaluating the target of DNS requests or the SNI/TLS header, not the country associated with the source IP. Because geography is an IP-based concept, wildcard FQDN cannot enforce geographic blocking and is the wrong tool here.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.