Courseiva
Firewall Policies and NAT →mediumMultiple Choice

NSE4 Firewall Policies and NAT Practice Question

An admin wants to block traffic from a specific geographic region (e.g., North Korea) from reaching the FortiGate's external interface. Which address object type should be used in the firewall policy?

⚠ Common exam trap

Test-takers frequently confuse geography address objects with subnet or FQDN objects, thinking they can manually list IP ranges for a country, but FortiGate requires the use of the built-in GeoIP database for country-based filtering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Geography address object

A geography address object allows the firewall to match traffic based on the source or destination IP address's registered country. FortiGate uses a built-in GeoIP database to map IP addresses to geographic regions, making it the correct choice for blocking traffic from a specific country like North Korea.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Subnet address object

    Why it's wrong here

    Subnet address objects in FortiOS define a fixed IP range using a network address and prefix length (e.g., 192.0.2.0/24) or explicit start/end addresses. Because they require manual, static input of every IP range, they cannot dynamically reflect the constantly changing IP allocations for an entire country or region. Blocking a specific geography by subnet would be impractical and incomplete, so this object type is the wrong choice.

  • ✓

    Geography address object

    Why this is correct

    A geography address object in FortiOS matches traffic based on the country or region mapped to the source or destination IP address, using the FortiGuard GeoIP database. When you add it to a firewall policy as the source address and set the action to DENY, all traffic originating from that geopolitical area is blocked dynamically, with no need to track individual IP ranges. This is the correct object type because it directly maps IP addresses to geographic locations.

  • ✗

    FQDN address object

    Why it's wrong here

    An FQDN address object resolves a fully qualified domain name, such as www.example.com, to its current IP address(es) and then uses those resolved addresses for policy matching. It cannot represent the entire IP space attributed to a country; instead it matches only the specific hostname's addresses, making it useful for domain-based control but not for geography-based blocking. Therefore, it is not suitable for blocking traffic from a geographic region.

  • ✗

    Wildcard FQDN address object

    Why it's wrong here

    A wildcard FQDN address object matches domain names and their subdomains using wildcard patterns, such as *.example.com, without any relation to IP address geolocation. This object type operates purely at the domain-name level, evaluating the target of DNS requests or the SNI/TLS header, not the country associated with the source IP. Because geography is an IP-based concept, wildcard FQDN cannot enforce geographic blocking and is the wrong tool here.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.