NSE4 System and Network Administration Practice Question
An administrator needs to configure a FortiGate to allow web traffic from the internal network to the Internet. The internal network is 192.168.1.0/24 and the WAN interface is port1 with IP 203.0.113.1. Which firewall policy is correct?
⚠ Common exam trap
Many exam-takers confuse the source and destination interfaces in a policy, thinking the destination should be the internal network instead of the WAN interface for outbound traffic, or they select Service: ALL to avoid missing any protocol, ignoring the requirement for web traffic only.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Source: internal, Destination: port1, Service: HTTP/HTTPS, Action: ACCEPT
The firewall policy must match traffic originating from the internal network (source: internal) destined for the Internet via the WAN interface (destination: port1), and the service must be restricted to HTTP/HTTPS to allow web traffic only. The action ACCEPT permits the traffic. This aligns with the standard stateful inspection flow where source and destination interfaces are defined based on traffic direction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Source: internal, Destination: port1, Service: HTTP/HTTPS, Action: ACCEPT
Why this is correct
This policy correctly implements outbound web access: traffic originates from the internal network, exits via the port1 interface that connects to the Internet, and is restricted to HTTP/HTTPS services. Because FortiGate firewall policies are interface-based and stateful, this single policy also allows the corresponding return traffic from external web servers to flow back to the internal users without an explicit reverse rule. The Action ACCEPT ensures that the traffic is permitted, aligning with the required use case.
- ✗
Source: port1, Destination: internal, Service: HTTP/HTTPS, Action: ACCEPT
Why it's wrong here
Reversing the source and destination interfaces would create an inbound policy: traffic arriving on port1 (the external/Internet-facing interface) is allowed to reach the internal network. This would permit external users to access internal resources, which is the exact opposite of what the administrator needs—allowing internal users to reach the web. Additionally, for outbound web traffic, the source must be the internal network, not the external side, so this policy's direction is fundamentally incorrect.
- ✗
Source: external, Destination: internal, Service: HTTP/HTTPS, Action: ACCEPT
Why it's wrong here
This policy also describes inbound traffic, but it uses 'external' as the source and 'internal' as the destination, meaning it will allow external hosts to connect to internal servers over HTTP/HTTPS. Such a policy is typically used to expose an internal web server to the Internet (e.g., a DMZ or port-forwarding scenario), not to give internal users web access. Since the requirement is for internal users to initiate web requests, the source should be 'internal' and the destination should be the outgoing interface 'port1', making this option wrong in its traffic direction.
- ✗
Source: internal, Destination: port1, Service: ALL, Action: ACCEPT
Why it's wrong here
While this policy has the correct source and destination (internal to port1) and Action ACCEPT, it allows ALL services, not just HTTP/HTTPS. This violates the principle of least privilege because internal users would be able to send any traffic (e.g., Telnet, SSH, SMTP, or other protocols) to the Internet, significantly expanding the attack surface. The administrator's goal is to permit web browsing only, so the Service should be specifically limited to HTTP/HTTPS; using ALL is overly permissive and a common security misconfiguration.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.