nerdexam
Fortinet

NSE4 · Question #187

Which of the following statements describes the method of creating a policy to block access to an FTP site?

The correct answer is B. Create a firewall policy with destination address set to the IP address of the FTP site, the Service. To block access to an FTP site on a FortiGate, create a firewall policy that specifies the FTP site's IP address as the destination and the FTP service, then set the action to deny.

Submitted by thandi_sa· Apr 18, 2026Firewall Policies and Authentication

Question

Which of the following statements describes the method of creating a policy to block access to an FTP site?

Options

  • AEnable Web Filter URL blocking and add the URL of the FTP site to the URL Block list.
  • BCreate a firewall policy with destination address set to the IP address of the FTP site, the Service
  • CCreate a firewall policy with a protection profile containing the Block FTP option enabled.
  • DNone of the above.

How the community answered

(41 responses)
  • A
    15% (6)
  • B
    78% (32)
  • C
    5% (2)
  • D
    2% (1)

Why each option

To block access to an FTP site on a FortiGate, create a firewall policy that specifies the FTP site's IP address as the destination and the FTP service, then set the action to deny.

AEnable Web Filter URL blocking and add the URL of the FTP site to the URL Block list.

Web Filter URL blocking is primarily designed for HTTP/HTTPS traffic and is not typically used to block standard FTP protocol connections.

BCreate a firewall policy with destination address set to the IP address of the FTP site, the ServiceCorrect

To block an FTP site, a specific firewall policy should be configured with the destination address set to the FTP server's IP address and the service set to FTP (TCP ports 20/21), with the policy action explicitly set to DENY.

CCreate a firewall policy with a protection profile containing the Block FTP option enabled.

While protection profiles apply various security features, there is no direct 'Block FTP' option within a general protection profile to block an entire FTP site; direct service blocking is handled at the firewall policy level.

DNone of the above.

Option B correctly describes a valid method for blocking an FTP site.

Concept tested: FortiGate firewall policy for service blocking

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/209193/about-firewall-policies

Topics

#Firewall Policies#FTP Blocking#Service Configuration#Destination Address

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice