nerdexam
Fortinet

NSE4 · Question #269

Which of the following statements is correct based on the firewall configuration illustrated in the exhibit?

The correct answer is D. A user cannot access the Internet using any protocols unless the user has passed firewall. If a FortiGate firewall configuration requires user authentication for internet access, no traffic will be permitted until the user has successfully authenticated.

Submitted by marco_it· Apr 18, 2026Firewall Policies and Authentication

Question

Which of the following statements is correct based on the firewall configuration illustrated in the exhibit?

Exhibit

NSE4 question #269 exhibit

Options

  • AA user can access the Internet using only the protocols that are supported by user authentication.
  • BA user can access the Internet using any protocol except HTTP, HTTPS, Telnet, and FTP. These
  • CA user must authenticate using the HTTP, HTTPS, SSH, FTP, or Telnet protocol before they can
  • DA user cannot access the Internet using any protocols unless the user has passed firewall

How the community answered

(44 responses)
  • A
    7% (3)
  • B
    2% (1)
  • C
    14% (6)
  • D
    77% (34)

Why each option

If a FortiGate firewall configuration requires user authentication for internet access, no traffic will be permitted until the user has successfully authenticated.

AA user can access the Internet using only the protocols that are supported by user authentication.

After authentication, a user can access the Internet using any protocols allowed by the policy, not only those directly supporting the authentication method.

BA user can access the Internet using any protocol except HTTP, HTTPS, Telnet, and FTP. These

This statement is incorrect because if authentication is required, all specified protocols are blocked until authentication succeeds, without specific exceptions unless configured.

CA user must authenticate using the HTTP, HTTPS, SSH, FTP, or Telnet protocol before they can

While authentication might be initiated via certain protocols, the core principle is that all internet access is blocked until successful authentication, regardless of the protocol initiating the authentication.

DA user cannot access the Internet using any protocols unless the user has passed firewallCorrect

If a firewall policy is configured to require user authentication, any traffic matching that policy, regardless of protocol, will be denied passage through the FortiGate unit until the user has successfully completed the authentication process.

Concept tested: FortiGate Firewall Policy User Authentication

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/707412/configuring-firewall-policies

Topics

#Firewall Authentication#Firewall Policies#User Access Control#Internet Access

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice