nerdexam
Fortinet

NSE4 · Question #356

Which configuration objects can be selected for the Source filed of a firewall policy? (Choose two.)

The correct answer is A. FQDN address C. User or user group. The source field in a FortiGate firewall policy defines where traffic originates and can be specified using FQDN addresses or user/user group identities.

Submitted by stefanr· Apr 18, 2026Firewall Policies and Authentication

Question

Which configuration objects can be selected for the Source filed of a firewall policy? (Choose two.)

Exhibit

NSE4 question #356 exhibit

Options

  • AFQDN address
  • BIP pool
  • CUser or user group
  • DFirewall service

How the community answered

(32 responses)
  • A
    88% (28)
  • B
    9% (3)
  • D
    3% (1)

Why each option

The source field in a FortiGate firewall policy defines where traffic originates and can be specified using FQDN addresses or user/user group identities.

AFQDN addressCorrect

FQDN addresses are dynamic objects that can be used in firewall policies to represent a group of IP addresses associated with a specific domain name, allowing flexible source identification.

BIP pool

An IP pool is typically used for source NAT (SNAT) or destination NAT (DNAT) and defines a range of IP addresses for *translation*, not for specifying the *source* of traffic in a policy match.

CUser or user groupCorrect

User or user groups allow authentication-based policy enforcement, where the source of traffic is defined by the authenticated identity rather than just an IP address, providing granular access control.

DFirewall service

A firewall service defines the *destination port and protocol* of traffic, which is configured in the "Service" field of a firewall policy, not the "Source" field.

Concept tested: Firewall policy source object types

Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/325712/firewall-policies-and-security-profiles

Topics

#Firewall policy#Policy source#Address objects#User authentication

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice