20+ practice questions focused on Security Profiles — one of the most tested topics on the Fortinet NSE 4 Network Security Professional NSE4 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Security Profiles PracticeA network administrator notices that users cannot access HTTPS websites after enabling SSL inspection. The firewall policy allows the traffic, and the certificate is trusted on the clients. What is the most likely cause?
Explanation: If the client's browser has a proxy configured incorrectly, the traffic may bypass the firewall's SSL inspection. This can cause HTTPS access failures even though the CA certificate is trusted on the clients and the firewall policy allows the traffic. The firewall may not intercept the traffic if it goes through a proxy server that is not configured to apply SSL inspection.
A company wants to block downloads of executable files via HTTP and HTTPS while allowing other content. Which combination of security profiles should be applied to the firewall policy?
Explanation: To block executable file downloads over HTTP and HTTPS while allowing other content, a Web Filtering profile is required to filter based on URL category or content type, and an Antivirus profile is needed to scan and block files (such as .exe) within the HTTP/HTTPS stream. The Antivirus profile can detect and block executable files by file signature or MIME type, while Web Filtering controls access to download sites or file types. Together, they provide layered defense against malicious executable downloads without affecting other web content.
An administrator wants to inspect SSL traffic to a specific finance application that uses a custom port (9443) and a self-signed certificate. Which configuration is required?
Explanation: Deep inspection is required to decrypt and inspect SSL traffic using a self-signed certificate on a non-standard port. The FortiGate must trust the application's self-signed certificate by adding it to the trusted CA list; otherwise, the deep inspection proxy will fail to validate the certificate and drop the connection. Certificate inspection (Option A) only checks the certificate metadata without decrypting the payload, so it cannot inspect the actual application traffic.
Which TWO web filtering features can be used to block access to malicious websites? (Choose two.)
Explanation: FortiGuard category-based filtering (C) is correct because it uses FortiGuard's continuously updated cloud database to classify URLs into categories such as Malicious Websites, Phishing, and Botnet, allowing the firewall to block access to known malicious sites by category. Web rating override (D) is correct because an administrator can manually override the FortiGuard rating of a specific URL or domain and set it to a blocked category (for example, Malicious Websites), which then blocks access to that site even if FortiGuard has not yet classified it as malicious. Static URL filtering (A) is not the best answer here because it only matches a manually maintained list of specific URLs or patterns and does not dynamically identify newly discovered malicious sites. Application control (B) identifies and controls applications based on traffic signatures rather than URL reputation, so it is not a web filtering feature for blocking malicious websites. DNS filter (E) blocks or allows domains based on DNS query categorization, but in this context it is not one of the two marked web filtering features for blocking malicious websites.
Refer to the exhibit. The policy applies deep inspection, but users cannot access any HTTPS websites. The FortiGate CA certificate is installed on clients. What is the most likely cause?
Explanation: The policy uses the service 'HTTPS', which by default matches only TCP port 443. Deep inspection is applied only to traffic that matches the policy's service criteria. If users are trying to access HTTPS websites that use any port other than 443 (e.g., 8443, 9443), that traffic does not match the service and is not subjected to deep inspection. Since the deep inspection profile likely requires inspection for all HTTPS traffic (or has a default action to block non-inspected traffic), those connections fail. Therefore, the most likely cause is the narrow service definition, not a misconfiguration of the deep inspection profile itself.
+15 more Security Profiles questions available
Practice all Security Profiles questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Security Profiles. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Security Profiles questions on the NSE4 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Security Profiles is tested as part of the Fortinet NSE 4 Network Security Professional NSE4 blueprint. Practicing with targeted Security Profiles questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free NSE4 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Security Profiles is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Security Profiles practice session with instant scoring and detailed explanations.
Start Security Profiles Practice →