Courseiva
Firewall Policies and NAT →mediumMultiple Choice

NSE4 Firewall Policies and NAT Practice Question

When creating a firewall policy, an admin wants to ensure that traffic from a specific user group is allowed only during business hours (Monday to Friday, 09:00-18:00). Which object type must be configured and applied to the policy?

⚠ Common exam trap

Candidates often confuse security profiles (which can have time-based filtering for web categories) with the schedule object required at the policy level, but only the schedule object controls whether the entire policy is active.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A schedule object with a recurring schedule

To restrict traffic based on time, a firewall policy must reference a schedule object. A recurring schedule defines specific days and hours (e.g., Monday–Friday, 09:00–18:00) and is applied directly to the policy. This allows the FortiGate to permit or deny traffic based on the current time without additional profiles or user group modifications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A security profile with time-based filtering

    Why it's wrong here

    Security profiles in FortiOS (AV, IPS, web filter, etc.) enforce a specific inspection or filtering function on traffic that is already permitted by a firewall policy, but they have no time-based component to control when the policy itself is active. The profile is evaluated only after the policy matches, and it applies regardless of the time of day if the policy is always enabled. Therefore, attaching a security profile cannot restrict enforcement to specific hours; time-based access control must be implemented at the policy level using a schedule object.

  • ✓

    A schedule object with a recurring schedule

    Why this is correct

    A schedule object with a recurring schedule is the correct Fortinet approach because it explicitly defines days-of-week and time-of-day ranges that are then bound directly to the firewall policy. When a schedule is attached to a policy, the policy becomes active only during the configured time window, and the firewall automatically disables enforcement outside that period. This matches the administrator's requirement precisely, and no other object type in FortiOS provides this built-in time-enforcement capability for policy activation.

  • ✗

    A user group object with time restrictions

    Why it's wrong here

    User group objects in Fortinet group together user and user-group definitions for authentication and identity-based policy matching, but they do not contain any fields for time-of-day or day-of-week restrictions. A user group only determines which users are matched, not when the policy is enforced; time restrictions are an orthogonal concept. Even if you pair a user group with a schedule in a policy, it is the schedule object that controls the time window, not the user group itself, so this option is fundamentally incorrect.

  • ✗

    A traffic shaping policy with a time-based rule

    Why it's wrong here

    Traffic shaping policies in FortiOS are used to allocate bandwidth, prioritize traffic, or apply QoS guarantees, but they do not make allow/deny decisions and cannot determine when a firewall policy is active. While a traffic shaping policy can reference a schedule to define when shaping rules apply, that schedule does not affect the underlying firewall policy's enforcement window—it merely adjusts bandwidth behavior for traffic that is already allowed. Using a time-based traffic shaping rule would not ensure that the firewall policy itself is only active during specific hours.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.