Courseiva

NSE4 Firewall Policies and NAT Practice Question

Which of the following describes the implicit deny action in FortiGate firewall policies?

⚠ Common exam trap

Candidates often confuse the implicit deny with a user-created deny policy, thinking it can be moved or customized, when in fact it is a fixed, system-enforced rule that always resides at the end of the policy sequence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A default policy that denies all traffic unless explicitly allowed

In FortiGate firewall policies, the implicit deny is a default, system-generated rule that denies all traffic not explicitly permitted by any configured policy. It is always present at the end of the policy list and cannot be moved, modified, or deleted. This ensures that any traffic not matching an explicit 'accept' policy is automatically dropped, enforcing a default-deny security posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A policy that is automatically created when the first policy is added

    Why it's wrong here

    The implicit deny is not a policy that is automatically created when the first policy is added; it is an inherent security default that exists from the very beginning, even before any explicit policy is configured. The firewall always has this built-in fail-safe to drop packets that do not match any rule, regardless of how many policies have been created. Adding the first policy does not instantiate the implicit deny; it simply starts populating the ordered rulebase above that immutable fallback.

  • ✗

    A policy that denies traffic based on the source IP

    Why it's wrong here

    This description confuses an explicit deny policy with the implicit deny. An explicit deny policy can indeed be configured to match and drop traffic based on source IP, as well as other attributes like destination, service, and interfaces, and it will be evaluated at its position in the policy order. The implicit deny, by contrast, is not a user-configurable rule; it is a final catch-all that matches any traffic that has not matched an earlier explicit policy, irrespective of source IP, destination, or any other header fields. Thus, denying based on source IP is a specific action of a named policy, not the nature of the implicit default.

  • ✗

    A policy that denies all traffic and can be moved to any position

    Why it's wrong here

    The implicit deny cannot be moved or reordered; it is permanently fixed at the bottom of the firewall's policy table as the last evaluation step. After all explicit policies in ascending order have been checked, any packet that still has no match is dropped by this default. If it could be moved to any position, an administrator could accidentally place it above legitimate allow rules, which would break connectivity and defeat the purpose of a security policy; instead, it is the rigid, invisible final rule.

  • ✓

    A default policy that denies all traffic unless explicitly allowed

    Why this is correct

    This is the correct description: the implicit deny is a default, unmodifiable behavior that denies all traffic unless a preceding explicit policy explicitly allows it. The firewall processes policies from top to bottom; when the packet does not match any configured allow or deny rule, it falls through to this built-in default, which silently discards the packet. This enforces a default-deny security posture, ensuring that only traffic explicitly permitted by an administrator can pass through the interface pair.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.