NSE4 Firewall Policies and NAT Practice Question
An organization wants to implement least privilege for firewall policies. Which THREE best practices should be followed? (Choose three.)
⚠ Common exam trap
A common mix-up: candidates choose 'Use any any for source and destination to simplify management' (Option D) thinking it reduces administrative overhead, but this directly contradicts the principle of least privilege and is a common misconfiguration in FortiGate environments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Specify the exact services required (e.g., TCP/443, TCP/22)
Specifying exact services (e.g., TCP/443, TCP/22) enforces least privilege by allowing only the necessary protocols and ports, reducing the attack surface. In FortiGate firewall policies, this is configured under the 'Service' field, where you can select predefined services or create custom ones to match specific TCP/UDP port numbers. This prevents overly permissive rules that could expose services like SMB (TCP/445) or RDP (TCP/3389) unintentionally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a single schedule covering all days
Why it's wrong here
A single schedule that covers every day grants access around the clock, which directly violates least privilege because it permits traffic during off-hours when legitimate services are not needed. FortiGate policies support one-time, recurring, and daily schedules, so you should restrict the policy to specific time windows that match business or maintenance requirements. This narrows the window an attacker can use a compromised session.
- ✓
Specify the exact services required (e.g., TCP/443, TCP/22)
Why this is correct
Defining the exact services required, such as TCP/443 and TCP/22, restricts the protocol and port combinations that the firewall will permit, enabling a default-deny posture. FortiGate service objects can specify source/destination ports, protocol types, and even ICMP message types, ensuring that only necessary application traffic is allowed. This prevents attackers from using unapproved ports for lateral movement or command-and-control traffic.
- ✓
Apply security profiles (e.g., antivirus, IPS) to inspect allowed traffic
Why this is correct
Even when you have allowed only the required services, applying security profiles such as antivirus, IPS, and application control ensures that the permitted traffic is deeply inspected for malicious content and exploit attempts. FortiGate uses flow-based or proxy-based inspection modes to block known signatures and behavioral anomalies, reducing the residual risk of allowing any traffic. This is a defense-in-depth measure that supports least privilege by not assuming allowed traffic is benign.
- ✗
Use any any for source and destination to simplify management
Why it's wrong here
Specifying 'any' for both source and destination in a firewall policy permits every host on any interface to communicate with every other host, which completely negates least privilege. This removes the ability to isolate security zones or enforce microsegmentation, so a compromised edge system could reach internal databases or OT networks without restriction. FortiGate policies should always use specific address objects or groups to define exactly which hosts or subnets are allowed to talk.
- ✓
Use specific source and destination addresses
Why this is correct
Limiting a policy to specific source and destination addresses or address groups ensures that only the identified hosts or subnets can communicate, applying microsegmentation and shrinking the attack surface. This prevents an unexpected student subnet or unmanaged device from accessing internal servers, even if it somehow reaches the firewall. FortiGate address objects also support dynamic types like FQDN or interface subnets to keep policies accurate as your network changes.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.