nerdexam
Fortinet

NSE4 · Question #480

Which is NOT true about source matching with firewall policies?

The correct answer is E. A source user/group and device must be specified in the firewall policy. It is not true that both a source user/group and a source device must be specified in a FortiGate firewall policy; these are distinct, optional criteria for source matching.

Submitted by priya_blr· Apr 18, 2026Firewall Policies and Authentication

Question

Which is NOT true about source matching with firewall policies?

Options

  • AA source address object must be selected in the firewall policy.
  • BA source user/group may be selected in the firewall policy.
  • CA source device may be defined in the firewall policy.
  • DA source interface must be selected in the firewall policy.
  • EA source user/group and device must be specified in the firewall policy.

How the community answered

(48 responses)
  • A
    6% (3)
  • B
    2% (1)
  • C
    2% (1)
  • D
    2% (1)
  • E
    88% (42)

Why each option

It is not true that both a source user/group and a source device must be specified in a FortiGate firewall policy; these are distinct, optional criteria for source matching.

AA source address object must be selected in the firewall policy.

A source address object is a common and often essential element for defining the origin of traffic allowed or denied by a firewall policy.

BA source user/group may be selected in the firewall policy.

FortiGate supports user-based policies, allowing traffic to be matched and controlled based on authenticated users or user groups.

CA source device may be defined in the firewall policy.

Device identification and control are features of FortiGate, enabling policies to be applied based on the type of device initiating the connection.

DA source interface must be selected in the firewall policy.

A source interface is a fundamental component of a firewall policy, specifying the ingress interface from which the traffic originates.

EA source user/group and device must be specified in the firewall policy.Correct

Firewall policies allow granular control based on various source criteria, including source IP address, source interface, source user/group, and source device. However, you are not required to specify *both* a source user/group and a source device in the same policy; you can specify one, both, or neither (along with other criteria like source address).

Concept tested: FortiGate firewall policy source matching

Source: https://docs.fortinet.com/document/fortigate/7.4.0/admin-guide/339239/firewall-policies

Topics

#Firewall Policy#Source Matching#FortiGate Configuration#Policy Components

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice