nerdexam
Fortinet

NSE4 · Question #487

The FortiGate port1 is connected to the Internet. The FortiGate port2 is connected to the internal network. Examine the firewall configuration shown in the exhibit; then answer the question below…

The correct answer is D. DNS Internet access is always allowed, even for users that have not authenticated. FortiGate firewall policies, by default, allow essential services like DNS access even for unauthenticated users, while general internet access typically requires authentication. The exhibit implies a configuration where DNS is always permitted.

Submitted by thandi_sa· Apr 18, 2026Firewall Policies and Authentication

Question

The FortiGate port1 is connected to the Internet. The FortiGate port2 is connected to the internal network. Examine the firewall configuration shown in the exhibit; then answer the question below. Based on the firewall configuration illustrated in the exhibit, which statement is correct?

Exhibit

NSE4 question #487 exhibit

Options

  • AA user that has not authenticated can access the Internet using any protocol that does not
  • BA user that has not authenticated can access the Internet using any protocol except HTTP,
  • CA user must authenticate using the HTTP, HTTPS, SSH, FTP, or Telnet protocol before they
  • DDNS Internet access is always allowed, even for users that have not authenticated.

How the community answered

(42 responses)
  • A
    7% (3)
  • B
    5% (2)
  • C
    14% (6)
  • D
    74% (31)

Why each option

FortiGate firewall policies, by default, allow essential services like DNS access even for unauthenticated users, while general internet access typically requires authentication. The exhibit implies a configuration where DNS is always permitted.

AA user that has not authenticated can access the Internet using any protocol that does not

General unauthenticated internet access is typically restricted by firewall policies that require authentication, meaning not every protocol is allowed.

BA user that has not authenticated can access the Internet using any protocol except HTTP,

Similar to choice A, general internet access for unauthenticated users is usually restricted to specific services, not broadly allowing all but a few.

CA user must authenticate using the HTTP, HTTPS, SSH, FTP, or Telnet protocol before they

While specific protocols like HTTP/HTTPS can be used for authentication (e.g., captive portal), this statement is not universally true for *all* internet access and doesn't account for implicitly allowed services like DNS.

DDNS Internet access is always allowed, even for users that have not authenticated.Correct

FortiGate devices are designed to allow DNS traffic (UDP port 53) to external DNS servers by default, even for unauthenticated users. This ensures basic network functionality and name resolution, which is critical for other services and even for the authentication process itself, preventing a chicken-and-egg problem.

Concept tested: FortiGate default DNS behavior

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/526715/implicit-firewall-policies

Topics

#Firewall policies#User authentication#DNS access#Network services

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice