FortiGate Address Object Types: Subnet, FQDN, Geography
Which of the following is NOT a valid address object type in FortiGate?
⚠ Common exam trap
Watch out — candidates often confuse MAC address filtering (available in some security features like device identification) with a valid firewall address object type, leading them to incorrectly select a wrong answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MAC address
FortiGate address objects support Subnet, Wildcard FQDN, and Geography types, but MAC addresses are not a valid address object type. MAC addresses are used in other contexts like static ARP entries or DHCP reservations, not as firewall address objects.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Subnet
Why it's wrong here
A subnet address object in FortiOS defines a network by an IPv4/IPv6 address and prefix length, such as 192.168.1.0/24 or 2001:db8::/64. It is a core object type used for firewall policy source and destination matching, NAT, and routing. Because it represents a contiguous IP address block, it is unquestionably a valid address object type in Fortinet devices.
- ✗
Wildcard FQDN
Why it's wrong here
Wildcard FQDN is a legitimate address object type that matches a domain and its subdomains through a preceding wildcard pattern, such as '*.fortinet.com'. Unlike a simple FQDN that resolves to a single hostname, a wildcard FQDN is evaluated against DNS responses containing aliases matching the pattern. This object type is therefore valid and distinct in Fortinet firewall policies.
- ✗
Geography
Why it's wrong here
Geography address objects are valid in FortiOS and identify traffic by country, continent, or region using FortiGuard's geolocation database. When selected, the firewall derives the match from the source or destination IP's registered location rather than a static IP list. This allows policies to be applied globally, but it remains a recognized address object type and is not the correct answer.
- ✓
MAC address
Why this is correct
MAC addresses are not a valid address object type in FortiGate firewall policies because policy matching is based on IP addresses, ports, and interfaces, not Layer 2 hardware addresses. While FortiOS can track MAC addresses for DHCP reservations, device inventory, and wireless user identification, those contexts use separate mechanisms rather than the address object list. Since the question asks for something that cannot be defined as a policy address object, MAC address is the correct choice.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which address object type can be used to match traffic based on the source country?
easy- A.Wildcard FQDN
- B.FQDN
- ✓ C.Geography
- D.Subnet
Why C: The Geography address object type in FortiGate allows you to match traffic based on the source or destination country by using the ISO 3166-1 alpha-2 country codes. This is configured within a firewall policy to enforce geo-blocking or geo-allowance, leveraging FortiGuard's GeoIP database to map IP addresses to countries.
Variation 2. An admin wants to allow traffic only from specific countries to access a web server. Which type of address object should be used in the firewall policy?
easy- A.Subnet object
- ✓ B.Geography object
- C.FQDN object
- D.Wildcard FQDN object
Why B: The Geography object (also known as a GeoIP object) in FortiGate allows firewall policies to permit or deny traffic based on the source or destination country. This is the correct choice because the requirement is to filter traffic by country, which is exactly what Geography objects are designed for, using IP-to-country mappings maintained by FortiGuard.
Variation 3. Which address object type allows you to match traffic based on the domain name in the HTTPS SNI field?
easy- A.Geography
- ✓ B.Wildcard FQDN
- C.Subnet
- D.FQDN
Why B: The Wildcard FQDN address object type in FortiGate allows you to match traffic based on the domain name in the HTTPS Server Name Indication (SNI) field. Unlike a standard FQDN, which matches the exact domain, the Wildcard FQDN supports patterns like *.example.com, enabling policy enforcement for subdomains and dynamic hostnames within a domain.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.