Courseiva

NSE4 System and Network Administration Practice Question

An administrator is troubleshooting why traffic from a specific source IP is not being matched by a policy route. Which THREE steps should the administrator take to diagnose the issue?

⚠ Common exam trap

The trap here is that candidates often jump to modifying routing or firewall policies (Options A and B) instead of first verifying the policy route's matching criteria and order, which are the most common root causes of policy route mismatches.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify the source address object in the policy route matches the traffic's source IP.

The most fundamental step in troubleshooting a policy route mismatch is to verify that the source address object defined in the policy route exactly matches the source IP of the traffic. If the object is misconfigured (e.g., wrong subnet mask, incorrect IP range, or a typo), the traffic will never hit the policy route, regardless of other settings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable all firewall policies to test routing.

    Why it's wrong here

    Disabling all firewall policies would stop all traffic and does not isolate policy routing. In FortiOS, policy routing is evaluated before firewall policy lookup, so removing firewall rules has no effect on whether a specific source IP matches a policy route. This action introduces unnecessary downtime and only obscures the actual routing decision.

  • ✗

    Change the administrative distance of the default route to 0.

    Why it's wrong here

    Administrative distance is a routing-table metric used to select among competing routes to the same destination; it has no bearing on policy-route matching. Policy routes are not installed as regular routes in the RIB and are evaluated based on their own match criteria, not on administrative distance. Setting the default route's administrative distance to 0 would only affect static route precedence at the RIB level, not the policy-route lookup for a particular source IP.

  • ✓

    Verify the source address object in the policy route matches the traffic's source IP.

    Why this is correct

    Policy routes in FortiOS use address objects as match conditions, and the object must contain the exact source IP or subnet for the traffic in question. If the object is misconfigured—wrong subnet, incorrect IP, or a different object type—the policy route will be silently skipped. Verifying this match is the first step to confirm that the traffic can actually hit the intended policy route.

  • ✓

    Check the policy route list order and ensure the matching condition is above the default route.

    Why this is correct

    FortiOS evaluates policy routes sequentially, and the first matching entry in the list is the one applied. If a broad catch-all policy route or the default route appears earlier in the list, it will intercept the traffic before the source-specific rule is reached. Reordering so that the specific source-based entry sits above any generic/default entry ensures the intended next-hop is selected for that source IP.

  • ✓

    Use the 'diagnose debug flow' command to trace packet flow.

    Why this is correct

    The 'diagnose debug flow' command provides a real-time, step-by-step trace of a packet through the FortiOS forwarding pipeline. It shows whether the packet hits a policy route, which policy route matches, and then the subsequent firewall policy and routing-table decisions. This is the definitive way to observe why a specific source IP is not being policy-routed as expected.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.