nerdexam
Fortinet

NSE4 · Question #337

Which statement about the firewall policy authentication timeout is true?

The correct answer is D. It is an idle timeout. The FortiGate considers a user to be idle if it does not see any packets. Firewall policy authentication timeouts are idle timeouts, meaning the FortiGate will terminate an authenticated user's session if it detects no traffic from that user for the configured duration.

Submitted by yasin.bd· Apr 18, 2026Firewall Policies and Authentication

Question

Which statement about the firewall policy authentication timeout is true?

Options

  • AIt is a hard timeout. The FortiGate removes the temporary policy for a user's source IP address
  • BIt is a hard timeout. The FortiGate removes the temporary policy for a user's source MAC address
  • CIt is an idle timeout. The FortiGate considers a user to be idle if it does not see any packets
  • DIt is an idle timeout. The FortiGate considers a user to be idle if it does not see any packets

How the community answered

(34 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    3% (1)
  • D
    88% (30)

Why each option

Firewall policy authentication timeouts are idle timeouts, meaning the FortiGate will terminate an authenticated user's session if it detects no traffic from that user for the configured duration.

AIt is a hard timeout. The FortiGate removes the temporary policy for a user's source IP address

Authentication timeouts are typically idle timeouts, not hard timeouts, allowing sessions to remain active as long as traffic is continuously flowing.

BIt is a hard timeout. The FortiGate removes the temporary policy for a user's source MAC address

Authentication timeouts are typically idle timeouts, not hard timeouts, and the expiration is based on user inactivity rather than a fixed duration for a MAC address.

CIt is an idle timeout. The FortiGate considers a user to be idle if it does not see any packets

While largely correct, choice D is more general and accurate by stating "no packets from the user" rather than specifically "user's source IP address," as authentication applies to the user session.

DIt is an idle timeout. The FortiGate considers a user to be idle if it does not see any packetsCorrect

The firewall policy authentication timeout is an idle timeout, which means the FortiGate will consider a user idle and terminate their authenticated session if it does not receive any packets from that user for the specified duration.

Concept tested: Firewall authentication idle timeout behavior

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/331302/user-group-authentication-and-timeouts

Topics

#Firewall policies#Authentication timeout#Idle timeout#User authentication

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice