Courseiva

NSE4 Firewall Policies and NAT Practice Question

Exhibit

config firewall policy
    edit 0
        set name "Deny-All"
        set srcintf "any"
        set dstintf "any"
        set srcaddr "all"
        set dstaddr "all"
        set action deny
        set schedule "always"
        set service "ALL"
        set logtraffic all
    next
    edit 1
        set name "Allow-HTTP"
        set srcintf "internal"
        set dstintf "wan1"
        set srcaddr "10.0.0.0/8"
        set dstaddr "all"
        set action accept
        set schedule "always"
        set service "HTTP"
        set logtraffic all
    next
end

Refer to the exhibit. An administrator configures the policies as shown. Traffic from 10.0.0.0/8 to the internet on HTTP is denied. What is the most likely reason?

⚠ Common exam trap

Many exam-takers assume policies are evaluated based on a 'most specific match' logic rather than the actual sequential order, leading them to overlook the policy placement as the root cause.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Deny-All policy is placed above the Allow-HTTP policy

In FortiGate firewall policies, the first matching policy is applied to traffic. The Deny-All policy is placed above the Allow-HTTP policy, so traffic from 10.0.0.0/8 to the internet on HTTP matches the Deny-All policy first and is denied before reaching the Allow-HTTP policy. This is a classic policy ordering issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Allow-HTTP policy uses service HTTP but the traffic uses HTTPS

    Why it's wrong here

    The Allow-HTTP policy specifying service HTTP is actually correct for this scenario because the traffic in question is HTTP, not HTTPS. FortiOS service objects define both protocol and port, so HTTP (TCP 80) matches the HTTP traffic. If the traffic were HTTPS, this would cause a mismatch, but that contradicts the given premise. Therefore, the service configuration is not the issue.

  • ✓

    The Deny-All policy is placed above the Allow-HTTP policy

    Why this is correct

    In FortiOS, policy evaluation is top-down and first-match; the first policy whose source/destination/service matches the traffic is applied. The Deny-All policy has a lower sequence number (e.g., policy ID 0) and appears above the Allow-HTTP policy, so it matches all traffic and denies the HTTP session before the allow policy is ever evaluated. Specificity does not override order, so the deny-all wins.

  • ✗

    The Allow-HTTP policy has the wrong source interface

    Why it's wrong here

    The source interface is the FortiGate ingress interface for the traffic, and the exhibit shows the HTTP traffic arrives on the correct internal interface that is configured as the source of the Allow-HTTP policy. If the source interface were wrong, the policy would not even be considered for matching, but here the traffic does match the source requirement. The actual problem is that an earlier policy denies the traffic before this match can occur.

  • ✗

    The Allow-HTTP policy is disabled

    Why it's wrong here

    A disabled policy in FortiOS appears greyed out and is skipped entirely during policy matching. The exhibit shows the Allow-HTTP policy is enabled with no disabled icon, so it is active and capable of matching traffic. Even if it were disabled, simply enabling it would not resolve the issue because the Deny-All policy still sits above it and would continue to drop the traffic. Hence, the disabled state is not the cause.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.