nerdexam
Fortinet

NSE4 · Question #366

Which traffic can match a firewall policy's "Services" setting? (Choose three.)

The correct answer is A. HTTP C. DNS E. HTTPS. Firewall policies can match traffic based on common application-layer services like HTTP, DNS, and HTTPS, which are defined by specific ports and protocols.

Submitted by parkjh· Apr 18, 2026Firewall Policies and Authentication

Question

Which traffic can match a firewall policy's "Services" setting? (Choose three.)

Options

  • AHTTP
  • BSSL
  • CDNS
  • DRSS
  • EHTTPS

How the community answered

(36 responses)
  • A
    92% (33)
  • B
    3% (1)
  • D
    6% (2)

Why each option

Firewall policies can match traffic based on common application-layer services like HTTP, DNS, and HTTPS, which are defined by specific ports and protocols.

AHTTPCorrect

HTTP (Hypertext Transfer Protocol) traffic, typically using TCP port 80, is a common application-layer service that firewall policies can identify and control.

BSSL

SSL (Secure Sockets Layer) is a cryptographic protocol that secures communication, operating beneath application protocols like HTTPS, and is not directly a 'service' that a firewall policy matches in the same way as HTTP or DNS.

CDNSCorrect

DNS (Domain Name System) traffic, typically using UDP/TCP port 53, is a fundamental network service that firewall policies can match to manage name resolution queries.

DRSS

RSS (Really Simple Syndication) is a web feed format for content distribution, which operates over existing network services like HTTP, and is not a network service that a firewall policy directly inspects or matches.

EHTTPSCorrect

HTTPS (Hypertext Transfer Protocol Secure) traffic, typically using TCP port 443, is an encrypted application-layer service that firewall policies can specify for security and access control.

Concept tested: Firewall policy service matching

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/469446/firewall-policy

Topics

#Firewall Services#Network Protocols#Firewall Policies#Traffic Matching

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice