Courseiva
Firewall Policies and NAT →mediumMultiple Choice

NSE4 Firewall Policies and NAT Practice Question

An administrator wants to log all traffic that is denied by the implicit deny rule. How can this be achieved?

⚠ Common exam trap

Test-takers frequently assume the implicit deny rule can be modified to enable logging, but FortiOS does not allow any configuration changes to the implicit deny rule, so you must create an explicit deny policy above it to log denied traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a firewall policy with action DENY and enable logging, placed above the implicit deny

The implicit deny rule at the bottom of the firewall policy list cannot be modified to enable logging. To log traffic denied by the implicit deny, you must create an explicit firewall policy with action DENY and logging enabled, placed above the implicit deny rule. This explicit deny policy will match traffic that would otherwise hit the implicit deny, and because it is an explicit policy, logging can be enabled on it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a firewall policy with action ACCEPT and enable logging

    Why it's wrong here

    Setting a firewall policy to ACCEPT with logging enabled will allow traffic through and record permitted sessions, not the denied sessions you intend to capture. Since the goal is to log traffic denied by the implicit deny rule, an ACCEPT policy is the opposite of what is needed, and any traffic it matches will never hit the implicit deny, leaving no record of the denials.

  • ✗

    Enable logging on the implicit deny rule

    Why it's wrong here

    The implicit deny rule in FortiOS is a built-in, read-only policy that sits at the bottom of the policy list and cannot be modified or configured to enable logging. Even if you could enable logging on it, the implicit deny rule generates no per-policy log entries, so relying on it would provide no visibility into blocked traffic, making an explicit deny policy necessary for logging.

  • ✓

    Create a firewall policy with action DENY and enable logging, placed above the implicit deny

    Why this is correct

    Creating an explicit firewall policy with DENY action and enabling logging, then placing it above the implicit deny rule, meets the administrator's requirement. This explicit policy will match traffic that would otherwise fall through to the implicit deny, block it, and generate a traffic log entry with details such as source, destination, and service. Because the policy is above the implicit deny, it takes precedence and ensures that denied traffic is properly logged.

  • ✗

    Use the 'diagnose debug flow' command to capture all traffic

    Why it's wrong here

    The 'diagnose debug flow' command is a real-time troubleshooting tool that traces individual packets through the FortiGate kernel, not a persistent logging mechanism. It requires manual activation and filtering for specific sessions, and it does not write to the traffic log or retain historical denial records. Therefore, it cannot be used to log all traffic denied by the implicit deny rule on an ongoing basis.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.