Courseiva
Firewall Policies and NAT →mediumMultiple Choice

NSE4 Firewall Policies and NAT Practice Question

An admin wants to ensure that VoIP traffic (UDP ports 5060-5061) from the internal network to the internet is prioritized over other traffic when the WAN link is congested. Which feature should be configured on the firewall policy?

⚠ Common exam trap

Candidates often confuse DSCP marking (which only tags packets for external QoS) with local traffic shaping that actually enforces bandwidth guarantees and priority on the FortiGate itself, leading them to choose option B instead of C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Traffic shaping policy with a guaranteed bandwidth allocation and high priority

A traffic shaping policy with guaranteed bandwidth allocation and high priority ensures that VoIP traffic (UDP ports 5060-5061) receives the necessary bandwidth and is prioritized over other traffic during WAN congestion. Traffic shaping policies on FortiGate allow you to set guaranteed bandwidth, maximum bandwidth, and priority levels, which directly address congestion by reserving resources for critical traffic like VoIP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable NAT on the policy

    Why it's wrong here

    Enabling NAT on the firewall policy only translates IP addresses/ports; it does not alter the FortiGate's scheduling or queueing behavior for UDP 5060 traffic. NAT cannot assign bandwidth guarantees, set priority levels, or protect VoIP packets from being dropped during congestion. Since NAT lacks any QoS mechanism, it is not a valid solution for prioritizing voice traffic.

  • ✗

    QoS marking only (DSCP)

    Why it's wrong here

    QoS marking alone (e.g., setting DSCP EF on SIP/RTP packets) merely tags packets for downstream routers; it does not change how the FortiGate itself queues or schedules that traffic. Without a traffic shaping policy that maps DSCP values to a high-priority queue or allocates guaranteed bandwidth, the local forwarding engine treats VoIP as best-effort. Moreover, if ISP or intermediate devices re-mark or ignore DSCP, the marking provides no end-to-end Class-of-Service guarantee.

  • ✓

    Traffic shaping policy with a guaranteed bandwidth allocation and high priority

    Why this is correct

    A traffic shaping policy is the only mechanism in FortiGate that can enforce both bandwidth reservations and queue priority for VoIP. By configuring a shaping profile with guaranteed bandwidth (e.g., 512 kbps) and setting priority to High, you instruct the traffic scheduler to service SIP/RTP UDP packets ahead of lower-priority flows and reserve capacity so that congestion does not starve voice. Guaranteed bandwidth ensures a minimum threshold, while high priority reduces jitter and latency, making this the correct choice for real-time traffic.

  • ✗

    Configure a security profile with QoS settings

    Why it's wrong here

    Security profiles (AV, IPS, app control, web filter) are designed for inspection and enforcement of application/URL policies; they contain no QoS-related fields such as bandwidth or queue priority. Attaching a security profile to the VoIP policy would inspect the UDP traffic (possibly adding latency) but would not in any way prioritize it. FortiGate handles QoS separately through traffic shaping policies, so this option is invalid for the stated goal.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.