nerdexam
Fortinet

NSE4 · Question #109

Which statement regarding the firewall policy authentication timeout is true?

The correct answer is A. It is an idle timeout. The FortiGate considers a user to be "idle" if it does not see any packets. The firewall policy authentication timeout is an idle timeout, where the FortiGate determines a user is idle if no packets are seen from their authenticated session.

Submitted by alyssa_d· Apr 18, 2026Firewall Policies and Authentication

Question

Which statement regarding the firewall policy authentication timeout is true?

Options

  • AIt is an idle timeout. The FortiGate considers a user to be "idle" if it does not see any packets
  • BIt is a hard timeout. The FortiGate removes the temporary policy for a user's source IP address
  • CIt is an idle timeout. The FortiGate considers a user to be "idle" if it does not see any packets
  • DIt is a hard timeout. The FortiGate removes the temporary policy for a user's source MAC address

How the community answered

(52 responses)
  • A
    90% (47)
  • B
    2% (1)
  • C
    6% (3)
  • D
    2% (1)

Why each option

The firewall policy authentication timeout is an idle timeout, where the FortiGate determines a user is idle if no packets are seen from their authenticated session.

AIt is an idle timeout. The FortiGate considers a user to be "idle" if it does not see any packetsCorrect

The authentication timeout for firewall policies in FortiGate is primarily an idle timeout. The FortiGate marks a user's session as idle when no traffic is detected originating from that user for the configured duration, eventually logging them out and requiring re-authentication for subsequent traffic.

BIt is a hard timeout. The FortiGate removes the temporary policy for a user's source IP address

It is an idle timeout, not a hard timeout; a hard timeout disconnects after a fixed duration regardless of activity.

CIt is an idle timeout. The FortiGate considers a user to be "idle" if it does not see any packets

The statement provided for C is identical to A in the given prompt, implying a question data issue, but the concept of an idle timeout based on packet activity is correct.

DIt is a hard timeout. The FortiGate removes the temporary policy for a user's source MAC address

It is an idle timeout, not a hard timeout, and authentication is typically tied to the user's source IP address, not their MAC address, for firewall policies.

Concept tested: FortiGate firewall policy authentication timeout type

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/245846/two-factor-authentication

Topics

#Firewall policy authentication#Authentication timeout#Idle timeout#FortiGate sessions

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice