Courseiva
Security Profiles →mediumMatching

NSE4 Security Profiles Practice Question

Match each FortiGate firewall policy action to its result.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Allows traffic matching the policy

Blocks traffic and sends a reset or ICMP unreachable

Routes traffic into an IPsec VPN tunnel

Routes traffic into an SSL VPN tunnel

Logs traffic without enforcing action (used for learning)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ACCEPT: Allows traffic that matches the policy

The correct matches are ACCEPT for allowing traffic and DENY for silently dropping traffic. Common confusions include mixing ACCEPT with REJECT (which sends a reset) and assuming DENY logs traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ACCEPT: Allows traffic that matches the policy

    Why this is correct

    In FortiGate firewall policies, the ACCEPT action (also known as 'accept' in the policy action field) permits all matching traffic to pass through the firewall from source to destination, subject to any additional security profiles (like antivirus, IPS, or web filtering) attached to the policy. This is the only action that actively forwards traffic between interfaces, and it can also be paired with logging to record session starts or closes. Unlike DENY or REJECT, ACCEPT does not generate any blocking notification or reset packets—it simply allows the session to be established and traffic to flow bidirectionally for the session.

  • ✓

    DENY: Silently drops traffic that matches the policy

    Why this is correct

    The DENY action silently discards all packets that match the policy's criteria, essentially dropping them at the firewall without sending any response back to the source host. This means the source TCP sender will not receive a TCP RST or ICMP unreachable message, so it will rely on its own retransmission timeout to eventually give up, which can cause perceived delays. In FortiGate, this is equivalent to 'deny' in the policy action and is commonly used for restricting traffic while avoiding unnecessary network probes from attackers.

  • ✗

    ACCEPT: Drops traffic and sends a TCP reset

    Why it's wrong here

    This statement describes the REJECT action, not ACCEPT. REJECT is a firewall policy action in FortiGate that actively sends a TCP reset (RST) packet to the source (or an ICMP port-unreachable for UDP) before dropping the traffic, thereby providing immediate feedback to the sender. ACCEPT, in contrast, never drops matching traffic; it allows it through. So this option incorrectly attributes the behavior of REJECT to ACCEPT.

  • ✗

    DENY: Allows traffic and logs it

    Why it's wrong here

    This option incorrectly claims that DENY allows traffic and logs it. In FortiGate, DENY's sole purpose is to block matching traffic by silently dropping it; it cannot 'allow' anything. Logging is a separate, optional feature that can be enabled for any policy action (including both ACCEPT and DENY), and it is configured via policy log settings, not by the action itself. Moreover, if a DENY policy is logged, the log entry records that the traffic was denied, not that it was permitted.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.