nerdexam
Fortinet

FCP_FGT_AD-7.6 · Question #46

Refer to the exhibit. Why did FortiGate drop the packet?

The correct answer is D. It matched the default implicit firewall policy. The debug trace output shows that the packet was "Denied by forward policy check (policy 0)." In FortiGate, policy ID 0 corresponds to the default implicit deny policy. This means that if a packet does not match any configured firewall policies, it is denied by the default…

Submitted by fatima_kr· Apr 18, 2026Firewall policies and authentication

Question

Refer to the exhibit. Why did FortiGate drop the packet?

Exhibit

FCP_FGT_AD-7.6 question #46 exhibit

Options

  • AIt matched an explicitly configured firewall policy with the action DENY.
  • BIt failed the RPF check.
  • CThe next-hop IP address is unreachable.
  • DIt matched the default implicit firewall policy.

How the community answered

(46 responses)
  • A
    7% (3)
  • B
    2% (1)
  • C
    4% (2)
  • D
    87% (40)

Explanation

The debug trace output shows that the packet was "Denied by forward policy check (policy 0)." In FortiGate, policy ID 0 corresponds to the default implicit deny policy. This means that if a packet does not match any configured firewall policies, it is denied by the default implicit policy.

Topics

#Firewall policy#Implicit deny#Traffic processing#Default policy

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.6 Practice