NSE4 Firewall Policies and NAT Practice Question
Which statement about the implicit deny policy on a FortiGate is true?
⚠ Common exam trap
Test-takers frequently think the implicit deny can be modified or moved, confusing it with a regular policy, but FortiGate enforces it as an unchangeable last-resort rule that cannot be deleted, reordered, or altered.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It is always at the bottom of the policy list and denies all unmatched traffic
The implicit deny policy is a built-in, non-configurable security policy that resides at the very bottom of the FortiGate policy list. It automatically denies all traffic that does not match any explicit user-defined policy, ensuring that only explicitly permitted traffic is allowed through the firewall.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It is a user-configurable policy that can be deleted
Why it's wrong here
The implicit deny is a hard-coded, system-enforced fallback mechanism in FortiOS, not a configurable policy object. It does not appear in the editable policy table as a rule that can be created, modified, or deleted, and administrators cannot add or remove it. Its existence is guaranteed and embedded in the packet processing flow, so deleting it is impossible by design.
- ✗
It allows traffic that matches no other policy
Why it's wrong here
This statement is exactly opposite to the implicit deny's purpose. The implicit deny drops, rather than permits, any session that does not match an explicit firewall policy based on source, destination, and service. Policy evaluation in FortiOS works from top to bottom, and when no match is found, the implicit deny rejects the traffic, ensuring no unclassified packet is allowed through.
- ✗
It can be moved to a different position in the policy list
Why it's wrong here
The implicit deny has no actual slot in the policy database that can be reordered. FortiOS appends it automatically after the last explicit policy in the evaluation chain, making its position fixed at the tail of the list. Administrators cannot move it, either through the GUI or CLI, and attempting to place it elsewhere would undermine the fundamental default-deny security model.
- ✓
It is always at the bottom of the policy list and denies all unmatched traffic
Why this is correct
This is the correct statement. In FortiOS, the implicit deny is always located at the very end of the policy list, after every user-created policy, and serves as the final catch-all rule. During sequential policy lookup, if no explicit policy matches the traffic parameters, the implicit deny matches all remaining sessions and blocks them by discarding the packets, thereby enforcing a strict default-deny posture.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which statement about the implicit deny policy at the bottom of the firewall policy list is true?
easy- A.It only applies to traffic from the internet
- B.It can be edited to change the action to accept
- C.It is optional and can be removed
- ✓ D.It drops all traffic that does not match any explicit policy
Why D: The implicit deny policy is a built-in, unchangeable rule at the bottom of the FortiGate firewall policy list that drops all traffic not matching any explicit policy. It ensures that only explicitly permitted traffic is allowed, enforcing a default-deny security posture. This policy cannot be edited, removed, or reordered, and it applies to all traffic regardless of source.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.