NSE4 Firewall Policies and NAT Practice Question
Which address object type can be used to match traffic based on the source country?
⚠ Common exam trap
Candidates often confuse Geography with FQDN or Subnet, assuming that DNS resolution or IP ranges can inherently determine country, but only the Geography object leverages the dedicated GeoIP database for country-based matching.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Geography
The Geography address object type in FortiGate allows you to match traffic based on the source or destination country by using the ISO 3166-1 alpha-2 country codes. This is configured within a firewall policy to enforce geo-blocking or geo-allowance, leveraging FortiGuard's GeoIP database to map IP addresses to countries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wildcard FQDN
Why it's wrong here
Wildcard FQDN address objects match traffic using domain name patterns containing wildcards, such as *.example.com, and rely on DNS to resolve those names to IP addresses at the time of matching. Their decision logic is exclusively name-based, so they cannot determine or enforce policies based on the source or destination country of an IP address. This makes them unsuitable for geography-based traffic matching.
- ✗
FQDN
Why it's wrong here
FQDN address objects match traffic to a specific fully qualified domain name, like www.example.com, by resolving that name to its current IP address through DNS. They identify hosts by domain identity rather than the physical or geopolitical location of the IP address, so they cannot differentiate traffic originating from or destined to a particular country. Because a single domain can resolve to IPs in multiple countries via CDNs or geo-DNS, an FQDN object is not the right tool for geographic matching.
- ✓
Geography
Why this is correct
Geography address objects in FortiOS match traffic based on the country, continent, or region associated with an IP address, using the built-in GeoIP database. These objects directly support policies such as geo-blocking or allowing traffic from a specific nation, without requiring the administrator to enumerate IP ranges. This is the only object type in the list whose matching logic is explicitly based on the geopolitical location of the packet endpoints, making it the correct answer.
- ✗
Subnet
Why it's wrong here
Subnet address objects match traffic by specifying an exact IP range in CIDR notation, such as 192.168.1.0/24. While an administrator could theoretically define a subnet that falls within a particular country's IP allocation, the object itself contains no geographic awareness and cannot automatically associate an address with a nation. Maintaining country-accurate subnet lists manually is impractical and error-prone, so subnets are not the appropriate type for matching traffic based on geography.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.