Courseiva

NSE4 Firewall Policies and NAT Practice Question

Which of the following best describes a Virtual IP (VIP) in FortiGate?

⚠ Common exam trap

Candidates often confuse Virtual IP (Destination NAT) with IP Pool (Source NAT), as both involve address translation but serve opposite traffic directions; candidates often pick Option B thinking VIP is for outbound translation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A method to translate a public IP/port to a private IP/port for inbound traffic

A Virtual IP (VIP) in FortiGate is used for Destination NAT (DNAT), translating an incoming public IP address and port to a private IP address and port. This allows external hosts to access internal servers (e.g., web servers) using a public IP, while the server remains on a private RFC 1918 address. The VIP object is referenced in a firewall policy to permit the inbound traffic and perform the translation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A method to translate a public IP/port to a private IP/port for inbound traffic

    Why this is correct

    A FortiGate VIP maps an external public IP and port to an internal private IP and port, enabling inbound destination NAT for published services. This precisely matches the inbound translation definition rather than outbound source NAT or routing.

  • ✗

    A method to translate private source IPs to a public IP for outbound traffic

    Why it's wrong here

    Translating private source IPs to a public address for outbound traffic is source NAT via IP pools or central NAT, not a VIP. A VIP maps inbound destination addresses to internal servers; it is tempting because both perform address translation, but the direction and object type differ.

  • ✗

    A method to group multiple firewall policies

    Why it's wrong here

    Grouping firewall policies is achieved with policy blocks or interface zones, not a VIP. A VIP is a destination NAT object mapping a public address to an internal host; it is tempting because VIPs are referenced inside policies, but they never aggregate policies themselves.

  • ✗

    A method to load balance traffic across multiple WAN interfaces

    Why it's wrong here

    Load balancing across WAN interfaces is handled by SD-WAN or ECMP, not a VIP. A VIP performs destination NAT, mapping an external address to an internal server; it is tempting because both involve address translation, but the axis here is destination versus interface-path selection.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.