Courseiva
Firewall Policies and NATmediumMultiple ChoiceObjective-mapped

Block Traffic from Geographic Region: Using Geography Address Object

An admin wants to block all traffic from a specific geographic region. Which address object type should be used in the firewall policy source?

Quick Answer

The answer is the Geography address object type. This is correct because FortiGate firewalls leverage a built-in GeoIP database to classify IP addresses by their registered country or region, allowing policies to match traffic based on geographic location without manually listing subnets. When an admin needs to block all traffic from a specific geographic region, the Geography address object serves as the source in the firewall policy, enabling the firewall to evaluate each packet’s originating IP against the GeoIP data and deny it accordingly. On the Fortinet NSE 4 Network Security Professional NSE4 exam, this concept tests your understanding of how to implement location-based access control efficiently, often appearing in policy configuration scenarios where candidates must choose between Geography, FQDN, or IP Range objects. A common trap is selecting the IP Range object, which would require manually compiling every subnet in a region—a tedious and error-prone approach. Memory tip: think “Geo = global, no manual list needed.”

⚠ Common exam trap

Candidates often confuse Geography with IP range or subnet, thinking they can manually compile a list of all IPs for a region, but FortiGate's Geography object automates this via the GeoIP database and is the correct, scalable approach for geographic blocking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Geography

FortiGate firewalls include a built-in Geography address object type that allows policies to match traffic based on the source or destination IP address's registered country or region. This object uses GeoIP databases to classify IP addresses, enabling administrators to block or allow traffic from entire geographic areas without needing to manually list individual subnets or ranges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • FQDN

    Why it's wrong here

    FQDN matches domain names, not geography.

  • Subnet

    Why it's wrong here

    Subnet requires specifying IP ranges, not country.

  • IP range

    Why it's wrong here

    IP range is for contiguous IP addresses, not geography.

  • Geography

    Why this is correct

    Geography objects use IP geolocation to match traffic from specific countries.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every NSE4 question from scratch — 282 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An admin wants to block traffic from a specific geographic region (e.g., North Korea) from reaching the FortiGate's external interface. Which address object type should be used in the firewall policy?

medium
  • A.Subnet address object
  • B.Geography address object
  • C.FQDN address object
  • D.Wildcard FQDN address object

Why B: A geography address object allows the firewall to match traffic based on the source or destination IP address's registered country. FortiGate uses a built-in GeoIP database to map IP addresses to geographic regions, making it the correct choice for blocking traffic from a specific country like North Korea.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.