Courseiva
Security Profiles →mediumMatching

NSE4 Security Profiles Practice Question

Match each FortiGate NAT type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Translates private source IP to public IP for outbound traffic

Translates public destination IP to private IP for inbound traffic

Assigns a range of ports to a private IP for NAT

Translates IPv6 traffic to IPv4 and vice versa

Translates IPv4 traffic to IPv6

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Source NAT: Translates source IP addresses of packets originating from a private network.

Source NAT modifies source IP of outgoing packets; Destination NAT modifies destination IP of incoming packets; Static NAT provides one-to-one mapping; PAT enables many-to-one translation via ports. Distractors swap the descriptions of Source and Destination NAT.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Source NAT: Translates source IP addresses of packets originating from a private network.

    Why this is correct

    Source NAT is applied to outbound traffic, rewriting the source IP address from a private/internal address to a public address so that packets can be routed across the internet. On FortiGate, SNAT may be dynamic (using a pool or IP pool) or overloaded via PAT to share a single IP with multiple sessions. This translation is stateful: the firewall tracks the session so that reply packets from the external host can be translated back to the original private source.

  • ✓

    Destination NAT: Translates destination IP addresses of packets destined for a private network.

    Why this is correct

    Destination NAT is used for inbound traffic, translating the destination IP address in packets that are destined for a private network, such as a published server. A public IP or port is mapped to an internal private IP and port, allowing external clients to reach the server without exposing the entire private network. FortiGate Virtual IP (VIP) objects implement DNAT, and the firewall reverses the translation on return packets as part of the same stateful session.

  • ✓

    Static NAT: One-to-one mapping between a private IP and a public IP.

    Why this is correct

    Static NAT creates a permanent one-to-one correspondence between a private IP address and a public IP address, with no port translation involved. This mapping is configured manually and works in both directions, allowing an internal host to initiate outbound traffic and also to receive unsolicited inbound traffic from the internet. Because the mapping is fixed, static NAT is often used for servers or devices that require a consistent reachable public identity, but it consumes one public IP per private host.

  • ✓

    Port Address Translation (PAT): Maps multiple private IPs to a single public IP using different port numbers.

    Why this is correct

    Port Address Translation (PAT) extends NAT by multiplexing many internal private addresses onto one public IP address, rewriting both the source IP and the source TCP/UDP port in each outgoing packet. The FortiGate maintains a session table so that return traffic is demultiplexed back to the correct internal host based on the original port mapping. This is the default source-NAT behavior for most outbound internet traffic on FortiGate firewalls because it conserves public IPv4 addresses while still providing connectivity.

  • ✗

    Source NAT: Translates destination IP addresses of incoming packets.

    Why it's wrong here

    This statement incorrectly assigns destination-IP rewriting to Source NAT. Source NAT (SNAT) modifies the source IP address of packets leaving the private network, typically from a private RFC1918 address to a routable public IP. Rewriting the destination IP of incoming packets is the role of Destination NAT, often used to direct inbound traffic to an internal server. The direction of the translation is what distinguishes SNAT from DNAT.

  • ✗

    Destination NAT: Translates source IP addresses of outgoing packets.

    Why it's wrong here

    This answer reverses the actual function of Destination NAT. DNAT changes the destination IP address in packets arriving from the outside, translating a public address to a private server address for port forwarding or load balancing. Translating the source IP of outgoing packets is Source NAT, which is performed on traffic initiated from the private network. The key error is that DNAT acts on inbound direction and the destination field, not on outbound source fields.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.