Fortinet Fortigate Administrator FCP Fortigate 76 · Free Practice Question Medium

Question 5

Which two policies must be configured to allow traffic on a policy-based next-generation firewall (NGFW) FortiGate? (Choose two.)

  • A

    A. Firewall policy

  • B

    B. Policy rule

  • C

    C. Security policy

  • D

    D. SSL inspection and authentication policy

Reveal correct answers

Correct answers: C, D

Explanation

The correct answers are:

C. Security policy
D. SSL inspection and authentication policy

Explanation:

In a policy-based NGFW FortiGate, traffic control and security enforcement are managed using security policies instead of traditional firewall policies. The two essential policies required to allow traffic are:

  1. Security Policy (C) – In policy-based mode, FortiGate uses security policies to define how traffic is handled. These policies include criteria like source/destination, application control, intrusion prevention (IPS), and web filtering. Without a security policy, traffic will not be allowed.

  2. SSL Inspection and Authentication Policy (D) – Policy-based NGFW mode requires SSL/SSH inspection for deep packet inspection and authentication policies to control user access. This ensures secure encrypted traffic handling, especially for HTTPS-based applications.

Why Not the Other Options?

  • A. Firewall policy – In a policy-based NGFW mode, traditional firewall policies are not used to control traffic. Instead, traffic is managed through security policies.

  • B. Policy rule – FortiGate does not have a separate "policy rule" entity; policies themselves function as rules governing traffic flow.

Thus, in a policy-based NGFW FortiGate, you must configure both Security Policy (C) and SSL Inspection and Authentication Policy (D) to allow and secure traffic effectively.


Extra explanation:

NGFW policy based mode, you must configure a few policies to allow traffic:

SSL inspection & Authentication, Security policy.

Security policies work with SSL Inspection & Authentication policies to inspect traffic. To allow traffic from a specific user or user group, both Security and SSL Inspection & Authentication policies must be configured.

If you are using Policy Based Mode, SSL Inspection & Authentication (consolidated) and Security Policy are required to allow traffic.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need