Courseiva

NSE4 Firewall Policies and NAT Practice Question

Which statement about the implicit deny policy at the bottom of the firewall policy list is true?

⚠ Common exam trap

It's easy for candidates to think the implicit deny policy can be edited or removed because they confuse it with an explicit deny policy that they can create and modify, but the implicit deny is a fixed, unchangeable rule at the bottom of the list.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It drops all traffic that does not match any explicit policy

The implicit deny policy is a built-in, unchangeable rule at the bottom of the FortiGate firewall policy list that drops all traffic not matching any explicit policy. It ensures that only explicitly permitted traffic is allowed, enforcing a default-deny security posture. This policy cannot be edited, removed, or reordered, and it applies to all traffic regardless of source.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It only applies to traffic from the internet

    Why it's wrong here

    The implicit deny policy is not restricted to internet traffic; it applies equally to all traffic traversing the FortiGate firewall, regardless of source or destination zone, interface, or IP address. Its purpose is to serve as a catch-all rule for any packet that fails to match an explicit security policy, whether that traffic originates from the internal LAN, DMZ, or the internet. Thus, stating that it only affects internet-bound traffic incorrectly narrows its scope and misrepresents the firewall's default inspection behavior.

  • ✗

    It can be edited to change the action to accept

    Why it's wrong here

    The implicit deny policy is hard-coded into the FortiGate and cannot be edited to change its action to accept. It is not a configurable policy row; administrators cannot modify its action, schedule, or services, nor can they reorder it higher in the policy table. To allow traffic that would otherwise be implicitly denied, an explicit allow policy must be created and placed above the implicit deny, but the implicit deny itself remains immutable.

  • ✗

    It is optional and can be removed

    Why it's wrong here

    The implicit deny policy is a mandatory part of the FortiGate security policy, and it cannot be removed or turned off. Even if a FortiGate is configured with no explicit policies, the implicit deny will still block all traffic, making the firewall default-deny by design. Since it is always present, it is not optional, though administrators can effectively circumvent its effect by adding a permissive allow policy at the bottom of the explicit policy list.

  • ✓

    It drops all traffic that does not match any explicit policy

    Why this is correct

    This is precisely the behavior of the implicit deny policy: it drops (or denies) any traffic that does not match an explicit firewall policy. When a packet arrives, FortiGate evaluates the policy list from top to bottom; if no explicit policy matches, the packet falls through to this built-in final rule and is denied without generating an explicit log entry unless logging is enabled on the corresponding policy. This ensures that any unclassified or misconfigured traffic is blocked by default, upholding a least-privilege security model.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.