nse4_fgt-72 Exam QuestionsBrowse all questions from this exam

nse4_fgt-72 Exam - Question 21


Which three criteria can FortiGate use to look for a matching firewall policy to process traffic? (Choose three.)

Show Answer
Correct Answer: ABCE

To match a firewall policy, FortiGate uses various criteria defined in the policy settings. These include services defined in the firewall policy (such as IP protocol and port number), destination defined as Internet Services in the firewall policy (which can be specific IP addresses or broader internet services), and source defined as Internet Services in the firewall policy (which can also be specified by IP addresses or internet services). These criteria help FortiGate determine the appropriate policy to apply to the traffic.

Discussion

14 comments
Sign in to comment
raydel92Options: ACE
Sep 9, 2023

Correct: A. Services defined in the firewall policy C. Destination defined as Internet Services in the firewall policy E. Source defined as Internet Services in the firewall policy FortiGate Security 7.2 Study Guide (p.52): "When a packet arrives, how does FortiGate find a matching policy? Each policy has match criteria, which you can define using the following objects: • Incoming Interface • Outgoing Interface • Source: IP address, user, internet services • Destination: IP address or internet services • Service: IP protocol and port number • Schedule: Specific times to apply policy" Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html

Slash_JMOptions: ACE
Sep 1, 2023

FortiGate Security 7.2 Study Guide p.52 The policies are consulted from top to bottom, regardless of the Policy ID #. The first rule that matches is applied and subsequent rules are not evaluated. FortiGate matches the traffic using the following criteria: - Incoming Interface - Outgoing Interface - Source (IP Address, User, Internet Services) - Destination (IP Address or Internet Services) - Service (IP Protocol and Port number) - Schedule (Time that the packet connected to the FortiGate)

jberol
Jan 4, 2023

ACE is correct

chihebOptions: ACE
Jan 4, 2023

the correct answers are ACE.

indunil75
Jan 5, 2023

ACE is correct

leadacOptions: ACE
Jan 30, 2023

ACE - Policy ID does not define a matching criteria, it´s just for editing purposes, and there is no priority in the policies, only their order will affect the matching process.

geroboamoOptions: ACE
May 16, 2023

there is no priority to be defined in security policies, and the policy id is just for reference

Rich_Man_Rich
Jan 9, 2023

ACE is correct

Danny_BOptions: ACE
May 24, 2023

7.2 SEC 52

DriftandLunaOptions: ACE
Mar 2, 2023

ACE, firewall policy will match on services, source & destinaiton

EquianoOptions: ACE
Mar 23, 2023

ACE is correct!

PaulGoOptions: ACE
Apr 10, 2023

Correct A, C, E

rian00z_Options: ACE
Aug 17, 2023

ACE is correct

Cisco_SE_765Options: ACE
Jun 5, 2024

The correct ones are A,C,E