Courseiva
Firewall Policies and NATeasyMultiple ChoiceObjective-mapped

NSE4 Firewall Policies and NAT Practice Question

An administrator needs to allow outbound DNS traffic (UDP port 53) from multiple internal subnets to the internet. Which object type should be used to group the subnets into a single source in the firewall policy?

⚠ Common exam trap

Test-takers frequently confuse address groups with service groups, mistakenly thinking that grouping subnets is done via service objects, but service groups only define protocols and ports, not IP addresses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Address group

An address group is the correct object type to group multiple internal subnets into a single source in a firewall policy. In FortiGate, address groups allow you to combine multiple IP addresses or subnets (IPv4 or IPv6) into a logical group, which can then be referenced as the source in a single firewall policy. This simplifies administration by reducing the number of policies needed to allow outbound DNS traffic from multiple subnets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • VIP group

    Why it's wrong here

    A VIP group is used in destination NAT (port forwarding) configurations to consolidate multiple virtual IPs. It represents a target of inbound traffic, not a collection of source subnets, and it cannot be selected as a source address in a policy. For outbound DNS from multiple internal subnets, a VIP group is irrelevant because it doesn't define where traffic originates.

  • Schedule group

    Why it's wrong here

    A schedule group aggregates time windows (e.g., 'work hours' or 'weekends') that control when a policy is allowed to match. It contains no IP address or network information, so it cannot group subnets for source matching. Even if you created a schedule, it would only restrict when the policy is active, not define the source subnets for outbound DNS.

  • Address group

    Why this is correct

    An address group is the correct object because it bundles multiple address objects—such as subnets, IP ranges, and FQDNs—into a single named entity. This address group can then be used as the source field in an outbound policy, effectively allowing all internal subnets to initiate DNS queries. This is exactly what the administrator needs to match the source subnets for outbound UDP port 53 traffic.

  • Service group

    Why it's wrong here

    A service group is used to group protocol-port combinations (like UDP/53 for DNS) into a single service object, which is applied in the service column of a policy, not the source column. While the traffic in question uses UDP 53, the requirement is to group the source subnets, not the service port. Since the administrator's need is about the source addresses, a service group cannot fulfill that role.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 282 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.