nerdexam
Fortinet

NSE4 · Question #132

What are the valid sub-types for a Firewall type policy? (Select all that apply)

The correct answer is A. Device Identity B. Address C. User Identity. Firewall policies can be refined using sub-types such as Device Identity, Address, and User Identity to specify comprehensive matching criteria for traffic.

Submitted by kim_seoul· Apr 18, 2026Firewall Policies and Authentication

Question

What are the valid sub-types for a Firewall type policy? (Select all that apply)

Options

  • ADevice Identity
  • BAddress
  • CUser Identity
  • DSchedule
  • ESSL VPN

How the community answered

(53 responses)
  • A
    87% (46)
  • D
    6% (3)
  • E
    8% (4)

Why each option

Firewall policies can be refined using sub-types such as Device Identity, Address, and User Identity to specify comprehensive matching criteria for traffic.

ADevice IdentityCorrect

Device Identity allows policies to be applied based on the specific type or group of devices originating or receiving traffic, adding a layer of granular control.

BAddressCorrect

Address is a fundamental sub-type, defining source and destination IP addresses or IP address groups that a policy applies to.

CUser IdentityCorrect

User Identity enables the firewall to apply policies based on authenticated users or user groups, linking network access to specific user profiles.

DSchedule

Schedule is a component used *within* a firewall policy to define its active times, rather than being a policy sub-type itself.

ESSL VPN

SSL VPN is a type of secure connection or interface, not a sub-type category for defining firewall policy matching criteria.

Concept tested: FortiGate firewall policy sub-types/criteria

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/86277/firewall-policies

Topics

#Firewall Policies#Policy Elements#User Identity#Device Identity

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice