Fortinet Fortigate Administrator FCP Fortigate 76 · Free Practice Question Medium
Question 5
Which two policies must be configured to allow traffic on a policy-based next-generation firewall (NGFW) FortiGate? (Choose two.)
-
A
A. Firewall policy
-
B
B. Policy rule
-
C
C. Security policy
-
D
D. SSL inspection and authentication policy
Reveal correct answers
Correct answers: C, D
Explanation
The correct answers are:
C. Security policy
D. SSL inspection and authentication policy
Explanation:
In a policy-based NGFW FortiGate, traffic control and security enforcement are managed using security policies instead of traditional firewall policies. The two essential policies required to allow traffic are:
Security Policy (C) – In policy-based mode, FortiGate uses security policies to define how traffic is handled. These policies include criteria like source/destination, application control, intrusion prevention (IPS), and web filtering. Without a security policy, traffic will not be allowed.
SSL Inspection and Authentication Policy (D) – Policy-based NGFW mode requires SSL/SSH inspection for deep packet inspection and authentication policies to control user access. This ensures secure encrypted traffic handling, especially for HTTPS-based applications.
Why Not the Other Options?
A. Firewall policy – In a policy-based NGFW mode, traditional firewall policies are not used to control traffic. Instead, traffic is managed through security policies.
B. Policy rule – FortiGate does not have a separate "policy rule" entity; policies themselves function as rules governing traffic flow.
Thus, in a policy-based NGFW FortiGate, you must configure both Security Policy (C) and SSL Inspection and Authentication Policy (D) to allow and secure traffic effectively.
Extra explanation:
NGFW policy based mode, you must configure a few policies to allow traffic:
SSL inspection & Authentication, Security policy.
Security policies work with SSL Inspection & Authentication policies to inspect traffic. To allow traffic from a specific user or user group, both Security and SSL Inspection & Authentication policies must be configured.
If you are using Policy Based Mode, SSL Inspection & Authentication (consolidated) and Security Policy are required to allow traffic.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
