Courseiva

NSE4 Firewall Policies and NAT Practice Question

Which firewall policy matching parameter is evaluated FIRST when a packet arrives at a FortiGate interface?

⚠ Common exam trap

Many candidates assume source or destination address is checked first, confusing the FortiGate's policy evaluation order with that of other firewalls (e.g., Cisco ASA) where interface is not always the primary match key.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incoming interface

When a packet arrives at a FortiGate interface, the firewall policy lookup begins by matching the incoming interface. This is because the interface is the first parameter evaluated in the policy-matching sequence, as defined by FortiGate's session-based architecture. Only after the interface match is successful does the FortiGate proceed to evaluate source address, destination address, service, and schedule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Source address

    Why it's wrong here

    FortiGate's policy lookup does not start with the source address. On a new session, the firewall first selects the set of policies associated with the incoming interface (and, if configured, the outgoing interface) before examining any IP address fields. Within that interface-specific subset, the source address is compared to the policy's source address objects as part of the second stage, along with destination address. Thus, source address is evaluated only after the interface has already filtered the candidate policies, and it can never be the first matching parameter.

  • ✗

    Service

    Why it's wrong here

    Service is a higher-layer matching parameter that comes later in FortiGate's policy evaluation order. After the incoming interface and both source and destination addresses match a policy entry, the firewall then checks the service object, which typically maps to protocol, port, or ICMP types. Because service is an application-layer condition rather than a network-path selector, it is never evaluated first; the interface and address tuple must align before the service comparison is performed. This ordering ensures that a service mismatch can only be considered after the policy has already been narrowed to a specific interface and address pair.

  • ✗

    Schedule

    Why it's wrong here

    Schedule is a time-based criterion that FortiGate deliberately evaluates near the end of the policy matching sequence. Only after the incoming interface, source address, destination address, and service have all matched does the firewall consult the schedule object to see if the current time is within the allowed period. This late evaluation is important because schedule does not affect which policies are considered; it only acts as a final gatekeeper that can deny or allow the session once everything else aligns. Thus, schedule is among the last parameters checked, never the first.

  • ✓

    Incoming interface

    Why this is correct

    The incoming interface is the very first match criterion FortiGate uses for any new session. When a packet arrives, FortiGate uses the ingress interface (and egress interface for explicit proxy or multi-interface policies) to index into its policy list, which is organized by interface pairs. This interface selection happens before any consideration of source, destination, service, or schedule, and it drastically reduces the number of policies that need to be sequentially evaluated. Therefore, the incoming interface is the foundational discriminator in the policy matching hierarchy.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.