nerdexam
Fortinet

NSE4 · Question #107

The FortiGate port1 is connected to the Internet. The FortiGate port2 is connected to the internal network. Examine the firewall configuration shown in the exhibit; then answer the question below…

The correct answer is D. DNS Internet access is always allowed, even for users that has not authenticated. In FortiGate configurations using firewall policy authentication, DNS Internet access is typically always allowed, even for users who have not yet authenticated.

Submitted by asante_acc· Apr 18, 2026Firewall Policies and Authentication

Question

The FortiGate port1 is connected to the Internet. The FortiGate port2 is connected to the internal network. Examine the firewall configuration shown in the exhibit; then answer the question below. Based on the firewall configuration illustrated in the exhibit, which statement is correct?

Exhibit

NSE4 question #107 exhibit

Options

  • AA user that has not authenticated can access the Internet using any protocol that does not trigger
  • BA user that has not authenticated can access the Internet using any protocol except HTTP,
  • CA user must authenticate using the HTTP, HTTPS, SSH, FTP, or Telnet protocol before they can
  • DDNS Internet access is always allowed, even for users that has not authenticated.

How the community answered

(25 responses)
  • B
    4% (1)
  • C
    8% (2)
  • D
    88% (22)

Why each option

In FortiGate configurations using firewall policy authentication, DNS Internet access is typically always allowed, even for users who have not yet authenticated.

AA user that has not authenticated can access the Internet using any protocol that does not trigger

Without the exhibit, it is not possible to confirm that any protocol not triggering authentication would be allowed, as other policies could block them.

BA user that has not authenticated can access the Internet using any protocol except HTTP,

This statement is too broad; specific protocols would be allowed or denied based on the detailed policies in the exhibit, which is not provided.

CA user must authenticate using the HTTP, HTTPS, SSH, FTP, or Telnet protocol before they can

This statement is incorrect because, for functional purposes, DNS access is almost always allowed prior to full user authentication.

DDNS Internet access is always allowed, even for users that has not authenticated.Correct

In typical FortiGate deployments that utilize firewall policy authentication, DNS traffic (UDP port 53) is often permitted for unauthenticated users through a specific policy to ensure that devices can resolve hostnames necessary for network access and the authentication portal itself.

Concept tested: FortiGate firewall policy for unauthenticated DNS access

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/700813/firewall-policies

Topics

#Firewall Policy#Authentication#DNS#Unauthenticated Access

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice