NSE4 Firewall Policies and NAT Practice Question
Which firewall policy matching parameter is evaluated FIRST when a packet arrives at a FortiGate interface?
⚠ Common exam trap
Many candidates assume source or destination address is checked first, confusing the FortiGate's policy evaluation order with that of other firewalls (e.g., Cisco ASA) where interface is not always the primary match key.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incoming interface
When a packet arrives at a FortiGate interface, the firewall policy lookup begins by matching the incoming interface. This is because the interface is the first parameter evaluated in the policy-matching sequence, as defined by FortiGate's session-based architecture. Only after the interface match is successful does the FortiGate proceed to evaluate source address, destination address, service, and schedule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Source address
Why it's wrong here
FortiGate's policy lookup does not start with the source address. On a new session, the firewall first selects the set of policies associated with the incoming interface (and, if configured, the outgoing interface) before examining any IP address fields. Within that interface-specific subset, the source address is compared to the policy's source address objects as part of the second stage, along with destination address. Thus, source address is evaluated only after the interface has already filtered the candidate policies, and it can never be the first matching parameter.
- ✗
Service
Why it's wrong here
Service is a higher-layer matching parameter that comes later in FortiGate's policy evaluation order. After the incoming interface and both source and destination addresses match a policy entry, the firewall then checks the service object, which typically maps to protocol, port, or ICMP types. Because service is an application-layer condition rather than a network-path selector, it is never evaluated first; the interface and address tuple must align before the service comparison is performed. This ordering ensures that a service mismatch can only be considered after the policy has already been narrowed to a specific interface and address pair.
- ✗
Schedule
Why it's wrong here
Schedule is a time-based criterion that FortiGate deliberately evaluates near the end of the policy matching sequence. Only after the incoming interface, source address, destination address, and service have all matched does the firewall consult the schedule object to see if the current time is within the allowed period. This late evaluation is important because schedule does not affect which policies are considered; it only acts as a final gatekeeper that can deny or allow the session once everything else aligns. Thus, schedule is among the last parameters checked, never the first.
- ✓
Incoming interface
Why this is correct
The incoming interface is the very first match criterion FortiGate uses for any new session. When a packet arrives, FortiGate uses the ingress interface (and egress interface for explicit proxy or multi-interface policies) to index into its policy list, which is organized by interface pairs. This interface selection happens before any consideration of source, destination, service, or schedule, and it drastically reduces the number of policies that need to be sequentially evaluated. Therefore, the incoming interface is the foundational discriminator in the policy matching hierarchy.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.