NSE4 Firewall Policies and NAT Practice Question
What is the purpose of a schedule object in a firewall policy?
⚠ Common exam trap
A common mix-up: candidates confuse schedule objects with other time-related features like session timeouts or idle timeouts, or assume schedule objects can control bandwidth or application priority, when in fact they only control the policy's active time window.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To specify the time of day when the policy is effective
A schedule object in a FortiGate firewall policy defines the time range (e.g., specific hours, days of the week, or recurring intervals) during which the policy is active. When the current time falls outside the schedule, the policy is automatically disabled, allowing administrators to enforce time-based access control without manual intervention. This is distinct from other policy attributes like bandwidth shaping or session limits.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
To specify the time of day when the policy is effective
Why this is correct
A schedule object defines the time window (such as 09:00–17:00 on weekdays) during which a firewall policy may be enforced. In FortiOS, the schedule condition is evaluated when a new session is being established; if the current time falls outside the schedule, the policy will not match, and the permitted traffic will be denied or evaluated by subsequent policies. This allows administrators to apply time-based access control, such as blocking employee internet access after business hours.
- ✗
To set the bandwidth limit for the policy
Why it's wrong here
A schedule object purely controls temporal availability and has no effect on bandwidth or throughput. Bandwidth limiting is performed by traffic shaping policies or shaper objects, which set guaranteed and maximum bandwidth values for specific matches. Confusing these two mechanisms would incorrectly attribute a rate-limiting function to a time-window object, which only determines when a rule is allowed to match.
- ✗
To prioritize traffic based on application
Why it's wrong here
Prioritizing traffic based on application is achieved through application control classifiers, not schedule objects. Schedule objects do not inspect or classify traffic; they simply restrict the policy’s enforcement to a defined time interval. Application-based prioritization is done using application signatures and QoS marks or traffic shapers that operate on identified application traffic.
- ✗
To limit the number of concurrent sessions
Why it's wrong here
Limiting concurrent sessions is a resource-control feature configured via session limits (for example, per-source IP) or by setting the maximum number of sessions in a policy’s advanced settings, not by schedule objects. A schedule object only specifies when a policy is applicable; it does not count, throttle, or bound the number of simultaneous sessions. Session limits are enforced at the session table level, independent of the time of day.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.