NSE4 · Question #356
Which configuration objects can be selected for the Source filed of a firewall policy? (Choose two.)
The correct answer is A. FQDN address C. User or user group. The source field in a FortiGate firewall policy defines where traffic originates and can be specified using FQDN addresses or user/user group identities.
Question
Which configuration objects can be selected for the Source filed of a firewall policy? (Choose two.)
Exhibit
Options
- AFQDN address
- BIP pool
- CUser or user group
- DFirewall service
How the community answered
(32 responses)- A88% (28)
- B9% (3)
- D3% (1)
Why each option
The source field in a FortiGate firewall policy defines where traffic originates and can be specified using FQDN addresses or user/user group identities.
FQDN addresses are dynamic objects that can be used in firewall policies to represent a group of IP addresses associated with a specific domain name, allowing flexible source identification.
An IP pool is typically used for source NAT (SNAT) or destination NAT (DNAT) and defines a range of IP addresses for *translation*, not for specifying the *source* of traffic in a policy match.
User or user groups allow authentication-based policy enforcement, where the source of traffic is defined by the authenticated identity rather than just an IP address, providing granular access control.
A firewall service defines the *destination port and protocol* of traffic, which is configured in the "Service" field of a firewall policy, not the "Source" field.
Concept tested: Firewall policy source object types
Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/325712/firewall-policies-and-security-profiles
Topics
Community Discussion
No community discussion yet for this question.
