NSE4 Firewall Policies and NAT Practice Question
Which TWO statements about firewall policy order are true?
⚠ Common exam trap
Candidates often confuse the default action (implicit deny) with an allow-all, or they mistakenly think that logging can be performed by multiple policies after a match, when in reality only the matched policy's logging settings apply.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policies are evaluated in the order they appear (top-down)
FortiGate firewalls evaluate policies sequentially from top to bottom. The first policy that matches the packet's source, destination, service, and other attributes is applied, and no further policies are checked. This top-down evaluation is fundamental to policy design and troubleshooting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
If a packet does not match any policy, it is allowed by default
Why it's wrong here
In FortiGate, firewall policy evaluation ends with an implicit deny rule at the bottom of the policy list. If no explicit policy matches a packet, the packet is silently dropped, not allowed, because the default behavior is to deny unmatched traffic. This is a fundamental security measure to prevent unauthorized access.
- ✓
Policies are evaluated in the order they appear (top-down)
Why this is correct
FortiGate firewall policies are stored in an ordered sequence and are evaluated from top to bottom when a new session's first packet arrives. The first policy that matches the packet's attributes (source, destination, service, interface) is applied, and no further policies are checked. This first-match model ensures that the administrator's intended precedence dictates the outcome.
- ✗
A more specific policy should be placed below a less specific one to avoid shadowing
Why it's wrong here
In FortiGate's first-match evaluation, a more specific policy must be placed above a less specific one; otherwise the generic policy above will match first and shadow the specific rule, making it unreachable. The claim that specific policies should go below is the opposite of what is required for correct traffic control. Proper placement is critical to avoid accidental bypassing of security controls.
- ✗
Once a policy is matched, subsequent policies are still evaluated for logging purposes
Why it's wrong here
Once a packet matches a FortiGate policy, the session is bound to that specific policy, and all remaining policies in the sequence are skipped for that session. Logging is exclusively governed by the matched policy's log settings, not by subsequent policies. Therefore, no later policy can contribute log entries or actions for an already matched session, making this statement false.
- ✓
Policy order can be changed by dragging policies in the GUI or using CLI commands
Why this is correct
Administrators can reorder FortiGate firewall policies using the web GUI's drag-and-drop functionality or through CLI commands such as 'config firewall policy' and the 'move' verb. For example, you can move a policy before or after another policy to change its position in the evaluation order. This allows for on-the-fly adjustments to traffic filtering precedence without recreating policy definitions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.