Courseiva

NSE4 Firewall Policies and NAT Practice Question

Which statement about the implicit deny policy on a FortiGate is true?

⚠ Common exam trap

Test-takers frequently think the implicit deny can be modified or moved, confusing it with a regular policy, but FortiGate enforces it as an unchangeable last-resort rule that cannot be deleted, reordered, or altered.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It is always at the bottom of the policy list and denies all unmatched traffic

The implicit deny policy is a built-in, non-configurable security policy that resides at the very bottom of the FortiGate policy list. It automatically denies all traffic that does not match any explicit user-defined policy, ensuring that only explicitly permitted traffic is allowed through the firewall.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It is a user-configurable policy that can be deleted

    Why it's wrong here

    The implicit deny is a hard-coded, system-enforced fallback mechanism in FortiOS, not a configurable policy object. It does not appear in the editable policy table as a rule that can be created, modified, or deleted, and administrators cannot add or remove it. Its existence is guaranteed and embedded in the packet processing flow, so deleting it is impossible by design.

  • ✗

    It allows traffic that matches no other policy

    Why it's wrong here

    This statement is exactly opposite to the implicit deny's purpose. The implicit deny drops, rather than permits, any session that does not match an explicit firewall policy based on source, destination, and service. Policy evaluation in FortiOS works from top to bottom, and when no match is found, the implicit deny rejects the traffic, ensuring no unclassified packet is allowed through.

  • ✗

    It can be moved to a different position in the policy list

    Why it's wrong here

    The implicit deny has no actual slot in the policy database that can be reordered. FortiOS appends it automatically after the last explicit policy in the evaluation chain, making its position fixed at the tail of the list. Administrators cannot move it, either through the GUI or CLI, and attempting to place it elsewhere would undermine the fundamental default-deny security model.

  • ✓

    It is always at the bottom of the policy list and denies all unmatched traffic

    Why this is correct

    This is the correct statement. In FortiOS, the implicit deny is always located at the very end of the policy list, after every user-created policy, and serves as the final catch-all rule. During sequential policy lookup, if no explicit policy matches the traffic parameters, the implicit deny matches all remaining sessions and blocks them by discarding the packets, thereby enforcing a strict default-deny posture.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which statement about the implicit deny policy at the bottom of the firewall policy list is true?

easy
  • A.It only applies to traffic from the internet
  • B.It can be edited to change the action to accept
  • C.It is optional and can be removed
  • ✓ D.It drops all traffic that does not match any explicit policy

Why D: The implicit deny policy is a built-in, unchangeable rule at the bottom of the FortiGate firewall policy list that drops all traffic not matching any explicit policy. It ensures that only explicitly permitted traffic is allowed, enforcing a default-deny security posture. This policy cannot be edited, removed, or reordered, and it applies to all traffic regardless of source.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.