Courseiva

FortiGate Address Object Types: Subnet, FQDN, Geography

Which of the following is NOT a valid address object type in FortiGate?

⚠ Common exam trap

Watch out — candidates often confuse MAC address filtering (available in some security features like device identification) with a valid firewall address object type, leading them to incorrectly select a wrong answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MAC address

FortiGate address objects support Subnet, Wildcard FQDN, and Geography types, but MAC addresses are not a valid address object type. MAC addresses are used in other contexts like static ARP entries or DHCP reservations, not as firewall address objects.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Subnet

    Why it's wrong here

    A subnet address object in FortiOS defines a network by an IPv4/IPv6 address and prefix length, such as 192.168.1.0/24 or 2001:db8::/64. It is a core object type used for firewall policy source and destination matching, NAT, and routing. Because it represents a contiguous IP address block, it is unquestionably a valid address object type in Fortinet devices.

  • ✗

    Wildcard FQDN

    Why it's wrong here

    Wildcard FQDN is a legitimate address object type that matches a domain and its subdomains through a preceding wildcard pattern, such as '*.fortinet.com'. Unlike a simple FQDN that resolves to a single hostname, a wildcard FQDN is evaluated against DNS responses containing aliases matching the pattern. This object type is therefore valid and distinct in Fortinet firewall policies.

  • ✗

    Geography

    Why it's wrong here

    Geography address objects are valid in FortiOS and identify traffic by country, continent, or region using FortiGuard's geolocation database. When selected, the firewall derives the match from the source or destination IP's registered location rather than a static IP list. This allows policies to be applied globally, but it remains a recognized address object type and is not the correct answer.

  • ✓

    MAC address

    Why this is correct

    MAC addresses are not a valid address object type in FortiGate firewall policies because policy matching is based on IP addresses, ports, and interfaces, not Layer 2 hardware addresses. While FortiOS can track MAC addresses for DHCP reservations, device inventory, and wireless user identification, those contexts use separate mechanisms rather than the address object list. Since the question asks for something that cannot be defined as a policy address object, MAC address is the correct choice.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which address object type can be used to match traffic based on the source country?

easy
  • A.Wildcard FQDN
  • B.FQDN
  • ✓ C.Geography
  • D.Subnet

Why C: The Geography address object type in FortiGate allows you to match traffic based on the source or destination country by using the ISO 3166-1 alpha-2 country codes. This is configured within a firewall policy to enforce geo-blocking or geo-allowance, leveraging FortiGuard's GeoIP database to map IP addresses to countries.

Variation 2. An admin wants to allow traffic only from specific countries to access a web server. Which type of address object should be used in the firewall policy?

easy
  • A.Subnet object
  • ✓ B.Geography object
  • C.FQDN object
  • D.Wildcard FQDN object

Why B: The Geography object (also known as a GeoIP object) in FortiGate allows firewall policies to permit or deny traffic based on the source or destination country. This is the correct choice because the requirement is to filter traffic by country, which is exactly what Geography objects are designed for, using IP-to-country mappings maintained by FortiGuard.

Variation 3. Which address object type allows you to match traffic based on the domain name in the HTTPS SNI field?

easy
  • A.Geography
  • ✓ B.Wildcard FQDN
  • C.Subnet
  • D.FQDN

Why B: The Wildcard FQDN address object type in FortiGate allows you to match traffic based on the domain name in the HTTPS Server Name Indication (SNI) field. Unlike a standard FQDN, which matches the exact domain, the Wildcard FQDN supports patterns like *.example.com, enabling policy enforcement for subdomains and dynamic hostnames within a domain.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.