Courseiva

NSE4 Firewall Policies and NAT Practice Question

An administrator wants to restrict access to a web server from only specific countries. The FortiGate is located at the network edge. Which address object type should be used in the source field of the firewall policy?

⚠ Common exam trap

Test-takers frequently confuse Geography address objects with FQDN or Subnet objects, mistakenly thinking that a wildcard or domain-based object can filter by geographic location, when in fact only the Geography object leverages the FortiGate's GeoIP database for country-level matching.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Geography address object

A Geography address object allows the FortiGate to match traffic based on the source IP's country of origin, using the built-in GeoIP database. This is the only address object type that can restrict access by country without requiring manual IP range updates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    FQDN address object

    Why it's wrong here

    An FQDN address object represents a fully qualified domain name (e.g., www.example.com) that the FortiGate resolves to one or more IP addresses via DNS. Because the object is tied to DNS resolution, it cannot inherently identify the geographic origin of the client; it only maps a domain to IPs. Therefore, it cannot be used to restrict access based on a country, making it unsuitable for the stated requirement.

  • ✗

    Wildcard FQDN address object

    Why it's wrong here

    A wildcard FQDN address object matches multiple domain names using a leading wildcard (e.g., *.example.com) and is primarily used for domain-based policy matching. Its scope is limited to hostname patterns, not geographic boundaries. Since wildcard FQDNs resolve to domains—not to a country or geopolitical region—they fail to provide the country-level classification needed to restrict access by country.

  • ✓

    Geography address object

    Why this is correct

    A geography address object in FortiOS is explicitly designed for geo-IP filtering. It references a country or region (e.g., China or Europe) by leveraging FortiGuard's geolocation database to map an IP address to a country. When used in a firewall policy's source or destination, it allows or denies traffic based on the client's geographic location, making it the correct and direct approach for restricting web server access by country.

  • ✗

    Subnet address object

    Why it's wrong here

    A subnet address object defines a range of IPv4 or IPv6 addresses using CIDR notation (e.g., 10.0.0.0/8). Subnet objects are purely IP-based and contain no metadata about the physical location or ownership of those addresses. Unless the subnet coincides exactly with a country's IP allocation—which is rarely true for a broad web-facing scenario—a subnet object cannot reliably filter traffic by country, making it incorrect for this requirement.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.