NSE4 Firewall Policies and NAT Practice Question
A FortiGate admin wants to ensure that traffic destined to a specific web server is inspected by an IPS profile. Which configuration is necessary?
⚠ Common exam trap
Candidates often think IPS can be enabled directly on the policy or that a special policy action exists for IPS, but FortiGate requires IPS to be applied as a security profile, not as a policy attribute.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a security profile group containing the IPS profile and apply it to the policy
In FortiGate, IPS inspection is applied via a security profile group that includes the IPS profile, which is then attached to a firewall policy. The firewall policy itself does not have a direct 'enable IPS' toggle; instead, IPS profiles are part of the security profiles that must be explicitly assigned to the policy to inspect traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable IPS on the firewall policy directly
Why it's wrong here
IPS cannot be enabled directly on a firewall policy as a simple checkbox or attribute. On FortiGate, intrusion prevention is delivered through an IPS sensor, which is a type of security profile, and security profiles are attached to a policy only by referencing them in the policy's security profile settings or via a security profile group. There is no field directly labeled 'Enable IPS' on a firewall policy definition.
- ✗
Set the policy's action to 'IPS'
Why it's wrong here
A firewall policy's action is limited to ACCEPT, DENY, and in some modes IPsec or SSL-VPN tunnel actions; there is no 'IPS' action. The action determines whether traffic is permitted or blocked, while IPS inspection is a post-accept processing step applied through security profiles. Choosing 'IPS' as an action would be syntactically impossible and conceptually confusing, as IPS is not a disposition but an inspection capability.
- ✓
Create a security profile group containing the IPS profile and apply it to the policy
Why this is correct
The correct approach is to create a security profile group that contains the IPS sensor and then apply that group to the firewall policy governing traffic to the web server. This groups the IPS sensor with other inspection profiles, enabling layered UTM inspection on accepted traffic. When the policy action is ACCEPT and the profile group is attached, all matching sessions are inspected by the IPS engine against its configured signatures and rules.
- ✗
Configure a VIP for the web server
Why it's wrong here
A Virtual IP (VIP) is used for destination NAT, translating an external IP address and port to the internal web server's IP address and port. It does not invoke any security inspection, including IPS, because NAT and UTM inspection are separate functions in the FortiGate processing flow. Configuring only a VIP would allow traffic to reach the server without any IPS protection; you would still need to apply an IPS profile to the corresponding firewall policy.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.