NSE4 Firewall Policies and NAT Practice Question
Which TWO statements about firewall policy authentication are correct?
⚠ Common exam trap
Candidates often assume authentication is only for inbound traffic or that it happens after policy allowance, but FortiGate enforces authentication as a prerequisite to policy matching, not as a post-allowance step.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authentication can be configured on a per-policy basis
FortiGate firewall policies allow authentication to be enabled on a per-policy basis using the 'set auth-on-demand' or 'set auth-cert' options, which enforce user authentication before traffic is processed. This granular control enables administrators to apply authentication only to specific policies, such as those controlling access to sensitive resources, without affecting other traffic flows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Authentication cannot be used with FSSO
Why it's wrong here
FSSO (Fortinet Single Sign-On) is actually a supported authentication method for firewall policies. It collects user login information from Windows Active Directory (or other directory services) and synchronizes it with FortiGate, allowing user identity to be used in policy authentication. Therefore, authentication can indeed be used with FSSO, making this statement incorrect.
- ✗
Authentication is only supported for inbound traffic
Why it's wrong here
FortiGate does not restrict policy-based authentication to inbound traffic only. Outbound traffic, such as users accessing the internet, can also be subject to authentication, typically in proxy-based or NAT policies. This allows administrators to enforce user identity verification for both directions, so the claim that authentication is only supported inbound is false.
- ✓
Authentication can be configured on a per-policy basis
Why this is correct
Authentication settings are integrated directly into firewall policy configuration, allowing each individual policy to independently require user authentication. This per-policy toggle gives administrators flexibility to apply authentication only to specific source/destination pairs or services, while leaving other policies unauthenticated. It is accurate to state that authentication can be configured on a per-policy basis.
- ✓
Authentication can be based on local, LDAP, or RADIUS databases
Why this is correct
FortiGate supports multiple back-end authentication sources, including local accounts defined on the FortiGate itself, LDAP servers such as Active Directory, and RADIUS servers. When setting up policy authentication, an administrator selects which of these server types to use, and FortiGate validates user credentials against that defined database. This makes the statement about local, LDAP, or RADIUS databases correct.
- ✗
Authentication is performed after the traffic is allowed by the policy
Why it's wrong here
When a firewall policy has authentication enabled, FortiGate first intercepts the user's connection and prompts for credentials, typically via a web-based challenge, before allowing traffic based on the policy. Successful authentication is a prerequisite for the policy's allow action; only after the user is verified does traffic flow. Thus, authentication is performed before, not after, the policy allows traffic.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.