NSE4 Firewall Policies and NAT Practice Question
During a security audit, the administrator runs the command 'diagnose firewall policy list' and sees the following output: policy id=1: allow from port1 to port2, src=10.0.0.0/8, dst=any, action=accept policy id=2: deny from port1 to port2, src=10.0.0.0/8, dst=172.16.0.0/12, action=deny policy id=3: allow from port1 to port2, src=any, dst=any, action=accept A host with IP 10.0.1.5 sends traffic to 172.16.0.1. Which policy will match?
⚠ Common exam trap
Watch out — candidates often assume a deny rule with a more specific destination will override a broader allow rule, forgetting that FortiGate uses first-match logic based on policy ID order, not longest-prefix matching or specificity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policy 1
Policy 1 matches first because FortiGate evaluates policies sequentially by ID. The source 10.0.1.5 is within 10.0.0.0/8 and the destination is any, so policy 1 matches and accepts the traffic. Although policy 2 would also match (172.16.0.1 is within 172.16.0.0/12), it is not evaluated because the first matching policy is applied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Policy 3
Why it's wrong here
Policy 3 is not reached because FortiGate evaluates firewall policies sequentially from the top of the policy list and stops at the first matching policy. Since policy 1 already matches the traffic (source within 10.0.0.0/8 and destination any), policy 3, regardless of its own criteria, is never examined. The implicit ordering for a given interface pair is fixed by policy ID, and later policies only matter if no earlier one matched. Thus policy 3 cannot be the effective policy for this session.
- ✓
Policy 1
Why this is correct
Policy 1 is correct because FortiGate uses a first-match model: it scans the policy list top-down and applies the first policy whose source, destination, and services match the packet. The source address in the traffic is within the 10.0.0.0/8 address range and the destination is any, so policy 1 matches all conditions for this session. Even though policy 2 may be more specific, it is placed after policy 1 and is therefore shadowed; the firewall never evaluates it for this traffic. Therefore policy 1's action (permit or deny) is what the audit should record.
- ✗
Implicit deny
Why it's wrong here
The implicit deny rule is a default action that applies only when no explicit firewall policy matches the traffic. In this scenario, policy 1 explicitly matches the source and destination, so the firewall applies policy 1 immediately and never falls through to the implicit deny. FortiGate's implicit deny is not a policy entry in the list; it is the final catch-all when the traversal of all explicit policies fails to find a match. Because an explicit match exists, the implicit deny cannot be the result.
- ✗
Policy 2
Why it's wrong here
Policy 2 does not become the effective policy because FortiGate does not use a best-match algorithm; it uses the first matching policy in the order configured. Even if policy 2 has more specific source or destination objects that exactly match the session, policy 1 appears earlier and matches the same traffic with a broader source range. This earlier match stops the lookup, so policy 2's more specific definitions are never considered. In security audits, such shadowed policies can be identified as redundant or misordered, but they do not influence this traffic.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.