Fortinet Fortigate Administrator FCP Fortigate 76 · Free Practice Question Medium

Question 17

Refer to the exhibit.

Which statement about this firewall policy list is true?

  • A

    A. The firewall policies are listed by ingress and egress interfaces pairing view.

  • B

    B. LAN to WAN. WAN to LAN. and Implicit are sequence grouping view lists.

  • C

    C. The Implicit group can include more than one deny firewall policy.

  • D

    D. The firewall policies are listed by ID sequence view.

Reveal correct answer

Correct answer: B

Explanation

B. LAN to WAN, WAN to LAN, and Implicit are sequence grouping view lists.

Explanation:

The firewall policy list shown in the exhibit is organized into three distinct sections:

  1. LAN to WAN – Policies handling outbound traffic from the internal LAN to the internet.

  2. WAN to LAN – Policies handling inbound traffic from the internet to the internal LAN.

  3. Implicit – The default deny policy at the bottom of the list.

Each section groups related policies based on their traffic direction and interface pairing.

Why B is Correct?

The firewall policy list groups policies into LAN to WAN, WAN to LAN, and Implicit, indicating a sequence grouping view rather than an ID-based sequence.

  • Grouping by traffic direction makes it easier to manage policies and ensures logical separation of outbound, inbound, and implicit deny rules.

Why A is Incorrect?

The policies are NOT listed by ingress/egress interface pairs directly, but rather by traffic direction grouping.

  • If the list was by interface pairing, it would be sorted explicitly based on "From" and "To" interface combinations, which is not the case here.

Why C is Incorrect?

The Implicit group typically includes only one deny policy—the final implicit deny rule.

  • Additional deny rules can be manually created in other groups, but the default Implicit Deny policy is singular and applies to all unmatched traffic.

Why D is Incorrect?

The firewall policies are not sorted by ID sequence.

  • If they were sorted by ID sequence, policies would be listed in numerical order (0, 1, 2, 3, 4), but they are instead grouped by traffic direction (LAN to WAN, WAN to LAN, Implicit).

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need