Courseiva

NSE4 Firewall Policies and NAT Practice Question

Which TWO statements about firewall policy order are true?

⚠ Common exam trap

Candidates often confuse the default action (implicit deny) with an allow-all, or they mistakenly think that logging can be performed by multiple policies after a match, when in reality only the matched policy's logging settings apply.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Policies are evaluated in the order they appear (top-down)

FortiGate firewalls evaluate policies sequentially from top to bottom. The first policy that matches the packet's source, destination, service, and other attributes is applied, and no further policies are checked. This top-down evaluation is fundamental to policy design and troubleshooting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    If a packet does not match any policy, it is allowed by default

    Why it's wrong here

    In FortiGate, firewall policy evaluation ends with an implicit deny rule at the bottom of the policy list. If no explicit policy matches a packet, the packet is silently dropped, not allowed, because the default behavior is to deny unmatched traffic. This is a fundamental security measure to prevent unauthorized access.

  • ✓

    Policies are evaluated in the order they appear (top-down)

    Why this is correct

    FortiGate firewall policies are stored in an ordered sequence and are evaluated from top to bottom when a new session's first packet arrives. The first policy that matches the packet's attributes (source, destination, service, interface) is applied, and no further policies are checked. This first-match model ensures that the administrator's intended precedence dictates the outcome.

  • ✗

    A more specific policy should be placed below a less specific one to avoid shadowing

    Why it's wrong here

    In FortiGate's first-match evaluation, a more specific policy must be placed above a less specific one; otherwise the generic policy above will match first and shadow the specific rule, making it unreachable. The claim that specific policies should go below is the opposite of what is required for correct traffic control. Proper placement is critical to avoid accidental bypassing of security controls.

  • ✗

    Once a policy is matched, subsequent policies are still evaluated for logging purposes

    Why it's wrong here

    Once a packet matches a FortiGate policy, the session is bound to that specific policy, and all remaining policies in the sequence are skipped for that session. Logging is exclusively governed by the matched policy's log settings, not by subsequent policies. Therefore, no later policy can contribute log entries or actions for an already matched session, making this statement false.

  • ✓

    Policy order can be changed by dragging policies in the GUI or using CLI commands

    Why this is correct

    Administrators can reorder FortiGate firewall policies using the web GUI's drag-and-drop functionality or through CLI commands such as 'config firewall policy' and the 'move' verb. For example, you can move a policy before or after another policy to change its position in the evaluation order. This allows for on-the-fly adjustments to traffic filtering precedence without recreating policy definitions.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.