Courseiva

NSE4 Firewall Policies and NAT Practice Question

Which address object type can be used to match traffic based on the source country?

⚠ Common exam trap

Candidates often confuse Geography with FQDN or Subnet, assuming that DNS resolution or IP ranges can inherently determine country, but only the Geography object leverages the dedicated GeoIP database for country-based matching.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Geography

The Geography address object type in FortiGate allows you to match traffic based on the source or destination country by using the ISO 3166-1 alpha-2 country codes. This is configured within a firewall policy to enforce geo-blocking or geo-allowance, leveraging FortiGuard's GeoIP database to map IP addresses to countries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Wildcard FQDN

    Why it's wrong here

    Wildcard FQDN address objects match traffic using domain name patterns containing wildcards, such as *.example.com, and rely on DNS to resolve those names to IP addresses at the time of matching. Their decision logic is exclusively name-based, so they cannot determine or enforce policies based on the source or destination country of an IP address. This makes them unsuitable for geography-based traffic matching.

  • ✗

    FQDN

    Why it's wrong here

    FQDN address objects match traffic to a specific fully qualified domain name, like www.example.com, by resolving that name to its current IP address through DNS. They identify hosts by domain identity rather than the physical or geopolitical location of the IP address, so they cannot differentiate traffic originating from or destined to a particular country. Because a single domain can resolve to IPs in multiple countries via CDNs or geo-DNS, an FQDN object is not the right tool for geographic matching.

  • ✓

    Geography

    Why this is correct

    Geography address objects in FortiOS match traffic based on the country, continent, or region associated with an IP address, using the built-in GeoIP database. These objects directly support policies such as geo-blocking or allowing traffic from a specific nation, without requiring the administrator to enumerate IP ranges. This is the only object type in the list whose matching logic is explicitly based on the geopolitical location of the packet endpoints, making it the correct answer.

  • ✗

    Subnet

    Why it's wrong here

    Subnet address objects match traffic by specifying an exact IP range in CIDR notation, such as 192.168.1.0/24. While an administrator could theoretically define a subnet that falls within a particular country's IP allocation, the object itself contains no geographic awareness and cannot automatically associate an address with a nation. Maintaining country-accurate subnet lists manually is impractical and error-prone, so subnets are not the appropriate type for matching traffic based on geography.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.