If Internet Service is already selected as Destination in a firewall policy, which other configuration object can be selected for the Destination field of a firewall policy?
If Internet Service is already selected as Destination in a firewall policy, which other configuration object can be selected for the Destination field of a firewall policy?
When Internet Service is selected as the Destination in a firewall policy, it encompasses all IP addresses, ports, and protocols associated with that service. Because of this comprehensive nature, no other configuration object can be added to the Destination field. The firewall policy does not allow mixing regular address objects with Internet Service Database (ISDB) objects, and it does not permit selecting additional services since the ISDB objects already include the necessary services information.
Security p. 59 Answer B is correct
B. No other object can be added FortiGate Security 7.2 Study Guide (p.59): "When configuring your firewall policy, you can use Internet Service as the destination in a firewall policy, which contains all the IP addresses, ports, and protocols used by that service. For the same reason, you cannot mix regular address objects with ISDB objects, and you cannot select services on a firewall policy. The ISDB objects already have services information, which is hardcoded." D. User or User Group (incorrect because you can not use Users or Groups as Destination, just as Source and they actually can be mixed with ISDB objects) Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html
If Internet Service is selected as Destination - You cannot use Address in the Destination - You cannot select Service in the Firewall Policy Fortigate Security Study Guide v7.2, page 59
The answer is B
If you've ever made a policy, you know you can make the destination an IP address.
Correction, B is correct due to "If Internet Service is already selected".
Should be D. I tried it on firewall. When you already selected internet service, it will not accept other objects except of user or user group or another Internet service
Selected Answer: B. tried checking the destination, user or user group is not present to be selected.
B is the right answer