Courseiva
Firewall Policies and NAThardMultiple ChoiceObjective-mapped

NSE4 Firewall Policies and NAT Practice Question

An administrator configures a firewall policy with a schedule object that is set to 'Available: Mon-Fri 09:00-17:00'. At 10:00 AM on Saturday, users report they cannot access the resource. The administrator checks the policy list and sees the policy is enabled. What is the MOST likely reason?

⚠ Common exam trap

The trap here is that candidates may overlook the schedule's day-of-week restriction and assume the policy is simply 'enabled' means it should work, failing to recognize that a schedule object can limit traffic to specific days and times, making the policy inactive outside those windows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The schedule object only allows traffic on weekdays, and Saturday is not included

The schedule object is configured to allow traffic only from Monday to Friday, 09:00-17:00. Since Saturday is outside this range, the firewall policy will deny or not match the traffic, even though the policy is enabled. This is the most direct and likely reason for the access failure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The FortiGate's system time is incorrect

    Why it's wrong here

    While an incorrect system time can cause schedules to misbehave, the question states the schedule is 'Mon-Fri 09:00-17:00' and the traffic is on Saturday. Even if the time were off, it would need to be off by an entire day to exclude Saturday. The most direct reason is that Saturday is simply not in the schedule's allowed days, so the policy is inactive. Time skew would affect hour-by-hour behavior, not systematically exclude an entire day unless the clock is drastically wrong.

  • A deny policy with higher priority is blocking the traffic

    Why it's wrong here

    Without any indication of a separate deny policy, the default implicit deny at the end of the policy table is the only deny action in play. If a higher-priority deny policy existed, it would block traffic regardless of the schedule, but the scenario points to the schedule as the active restriction. Firewall policies are evaluated top-down; a deny rule would also typically generate a log entry, which is not mentioned. Since the schedule is correctly applied, the policy is simply inactive on Saturday, causing traffic to fall through to the implicit deny.

  • The schedule object is not correctly applied to the policy

    Why it's wrong here

    The admin has already applied the schedule to the policy; the problem is not misapplication but that the schedule's definition excludes Saturday. If the schedule were not applied, the policy would be active 24/7, so traffic would be allowed. The fact that traffic is denied on Saturday indicates the schedule is in effect and filtering by day-of-week. Thus, the schedule object is correctly applied, but its scope (Mon-Fri) is the limiting factor.

  • The schedule object only allows traffic on weekdays, and Saturday is not included

    Why this is correct

    The schedule object defined as 'Mon-Fri 09:00-17:00' explicitly restricts allowed days to Monday through Friday. On Saturday, the current time falls outside the schedule's active period, so the policy's schedule condition is not met. Consequently, the FortiGate skips this policy and evaluates subsequent policies, eventually hitting the implicit deny rule that drops the traffic. This is a standard behavior: a firewall policy with a time-based schedule is inactive outside its defined window.

About these practice questions

One of 282 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.