nse4_fgt-72 Exam QuestionsBrowse all questions from this exam

nse4_fgt-72 Exam - Question 73


If Internet Service is already selected as Destination in a firewall policy, which other configuration object can be selected for the Destination field of a firewall policy?

Show Answer
Correct Answer: B

When Internet Service is selected as the Destination in a firewall policy, it encompasses all IP addresses, ports, and protocols associated with that service. Because of this comprehensive nature, no other configuration object can be added to the Destination field. The firewall policy does not allow mixing regular address objects with Internet Service Database (ISDB) objects, and it does not permit selecting additional services since the ISDB objects already include the necessary services information.

Discussion

8 comments
Sign in to comment
NiciExamOption: B
Jul 19, 2023

Security p. 59 Answer B is correct

raydel92Option: B
Sep 13, 2023

B. No other object can be added FortiGate Security 7.2 Study Guide (p.59): "When configuring your firewall policy, you can use Internet Service as the destination in a firewall policy, which contains all the IP addresses, ports, and protocols used by that service. For the same reason, you cannot mix regular address objects with ISDB objects, and you cannot select services on a firewall policy. The ISDB objects already have services information, which is hardcoded." D. User or User Group (incorrect because you can not use Users or Groups as Destination, just as Source and they actually can be mixed with ISDB objects) Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html

Halmonte0780Option: B
Jul 23, 2023

If Internet Service is selected as Destination - You cannot use Address in the Destination - You cannot select Service in the Firewall Policy Fortigate Security Study Guide v7.2, page 59

TakumiOption: B
Jul 18, 2023

The answer is B

ccnax2Option: A
Jul 18, 2023

If you've ever made a policy, you know you can make the destination an IP address.

ccnax2
Jul 21, 2023

Correction, B is correct due to "If Internet Service is already selected".

dmvpnOption: D
Sep 27, 2023

Should be D. I tried it on firewall. When you already selected internet service, it will not accept other objects except of user or user group or another Internet service

dmvpnOption: B
Sep 27, 2023

Selected Answer: B. tried checking the destination, user or user group is not present to be selected.

GeniusAOption: B
Dec 26, 2023

B is the right answer