nerdexam
Fortinet

FCP_FGT_AD-7.6 · Question #130

An administrator wants to ensure that a specific firewall policy on FortiGate is matched before any other policies for the same traffic. Which configuration change is most appropriate?

The correct answer is C. Move the policy higher in the policy list. FortiGate evaluates firewall policies in a strict top-to-bottom order, applying the first matching policy it encounters (first-match wins). Moving the target policy to a higher position in the policy list ensures it is evaluated before competing policies for the same traffic…

Submitted by zhang_li· Apr 18, 2026Firewall policies and authentication

Question

An administrator wants to ensure that a specific firewall policy on FortiGate is matched before any other policies for the same traffic. Which configuration change is most appropriate?

Options

  • AEnable central NAT
  • BIncrease the policy ID number
  • CMove the policy higher in the policy list
  • DChange the policy schedule to always

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    93% (26)

Explanation

FortiGate evaluates firewall policies in a strict top-to-bottom order, applying the first matching policy it encounters (first-match wins). Moving the target policy to a higher position in the policy list ensures it is evaluated before competing policies for the same traffic. Policy ID numbers (B) are identifiers only and do not affect evaluation order-only position matters. Enabling central NAT (A) affects NAT processing, not policy match order. Changing the schedule (D) affects when the policy is active, not its match priority relative to other policies.

Topics

#Firewall policy order#Policy precedence#FortiGate policies#Traffic matching

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.6 Practice