NSE4 Security Profiles Practice Question
A company recently deployed FortiGate with application control to manage cloud application usage. They want to allow Google Drive for business but block personal Google accounts. Which application control configuration approach is most effective?
⚠ Common exam trap
Watch out — candidates often confuse web filtering (URL-based) with application control (signature-based), assuming that blocking a URL will effectively block personal accounts, but in reality, both account types use the same URL and only differ in application-layer metadata.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use application control with specific signatures for 'Google Drive Business' and 'Google Drive Personal' and apply appropriate actions.
FortiGate's application control uses application signatures to distinguish between different versions of the same application, such as 'Google Drive Business' and 'Google Drive Personal'. By configuring specific signatures with appropriate actions (allow for business, block for personal), you can enforce granular control over cloud application usage without affecting legitimate business traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use web filtering to block the URL of personal Google Drive.
Why it's wrong here
Web filtering categorizes URLs and domains, but Google Drive Personal and Business share many of the same URLs and infrastructure. This technique cannot inspect application-layer metadata or session tokens to distinguish a personal account from a business account. As a result, a URL-based block would either be circumvented by direct IP access or inadvertently block legitimate business use, so it is not an application-aware control.
- ✗
Configure IPS to block personal Google Drive traffic.
Why it's wrong here
IPS is designed to detect and prevent known vulnerability exploits and attack patterns, not to identify or control applications. While IPS may inspect payloads for malicious content, it lacks the granular signatures and protocol decoders needed to recognize 'Google Drive Personal' as a distinct application instance. Relying on IPS to block this traffic would fail to provide the required allow/block policy granularity and could generate false positives.
- ✓
Use application control with specific signatures for 'Google Drive Business' and 'Google Drive Personal' and apply appropriate actions.
Why this is correct
FortiOS Application Control leverages FortiGuard application signatures that identify Google Drive and its sub-versions, including 'Google Drive Business' and 'Google Drive Personal,' based on flow characteristics and OAuth/authentication context. By applying separate actions—such as block for the Personal signature and allow for the Business signature—the administrator can enforce a granular policy. Each signature is matched to the specific application instance using SSL inspection, enabling precise control that is unavailable with URL or vulnerability-based methods.
- ✗
Create a rule to block all Google Drive applications.
Why it's wrong here
Creating a rule to block all Google Drive applications would treat both business and personal usage identically, removing any ability to permit legitimate corporate use of Google Drive Business. This approach is technically valid as a broad blocking measure, but it is not the best answer because it lacks the granularity needed to enforce a policy that distinguishes between work and personal access. Applying signatures individually allows more precise matching, making this catch-all rule an overreaction.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.