Courseiva

NSE4 Firewall Policies and NAT Practice Question

An administrator needs to block all traffic from a specific geographic region. Which object type should be used as the source in the firewall policy?

⚠ Common exam trap

A common mix-up: candidates confuse geography objects with IP range or FQDN objects, mistakenly thinking they can manually compile IP ranges for a region or use domain-based filtering to block geographic traffic, which is inefficient and inaccurate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Geography address

A geography address object (also known as a geolocation object) allows the firewall to match traffic based on the source IP's registered country or region using GeoIP databases. This is the correct object type when the requirement is to block all traffic from a specific geographic region, as it evaluates the source IP against the FortiGate's built-in geolocation mapping.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    FQDN address

    Why it's wrong here

    An FQDN address object maps a fully qualified domain name to its resolved IP addresses, but it has no concept of geographic origin. When traffic matches an FQDN, FortiGate evaluates the hostname in the packet, not the source country, so it cannot be used to block all traffic from a specific country. Even if the FQDN resolves to an IP in that country, the policy is domain-based rather than geo-based, and it would miss traffic from other IPs in the same nation.

  • ✗

    IP range address

    Why it's wrong here

    An IP range address object requires manually defining a start and end IP, which could theoretically cover a country only if you enumerated every contiguous block in that nation. However, a country's IP space is composed of hundreds or thousands of non-contiguous prefixes managed by numerous ISPs, making this approach impractical and prone to outdated entries. IP range objects also lack intrinsic geolocation attributes, so FortiGate would not treat them as country-based even if they happened to cover a region.

  • ✗

    Wildcard FQDN address

    Why it's wrong here

    A wildcard FQDN address matches subdomains of a domain, such as *.example.com, and is resolved via DNS to filter by hostname patterns. It has no geographic awareness and cannot represent a country because it expresses only domain naming hierarchies, not IP geolocation. While it can block traffic to a domain, it cannot block all traffic from a specific country, which requires mapping source IP addresses to physical locations.

  • ✓

    Geography address

    Why this is correct

    A geography address (also called a geo-IP object) uses FortiGate's built-in IP geolocation database to associate source IP addresses with countries, regions, or continents. By creating a geography object for the target country and referencing it in a firewall policy source address, the administrator can block all traffic originating from any IP in that country without enumerating individual IPs. This object type updates dynamically when the geolocation database is refreshed, making it the correct and scalable choice for region-based blocking.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.