Courseiva

NSE4 Firewall Policies and NAT Practice Question

A FortiGate admin wants to ensure that traffic destined to a specific web server is inspected by an IPS profile. Which configuration is necessary?

⚠ Common exam trap

Candidates often think IPS can be enabled directly on the policy or that a special policy action exists for IPS, but FortiGate requires IPS to be applied as a security profile, not as a policy attribute.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a security profile group containing the IPS profile and apply it to the policy

In FortiGate, IPS inspection is applied via a security profile group that includes the IPS profile, which is then attached to a firewall policy. The firewall policy itself does not have a direct 'enable IPS' toggle; instead, IPS profiles are part of the security profiles that must be explicitly assigned to the policy to inspect traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable IPS on the firewall policy directly

    Why it's wrong here

    IPS cannot be enabled directly on a firewall policy as a simple checkbox or attribute. On FortiGate, intrusion prevention is delivered through an IPS sensor, which is a type of security profile, and security profiles are attached to a policy only by referencing them in the policy's security profile settings or via a security profile group. There is no field directly labeled 'Enable IPS' on a firewall policy definition.

  • ✗

    Set the policy's action to 'IPS'

    Why it's wrong here

    A firewall policy's action is limited to ACCEPT, DENY, and in some modes IPsec or SSL-VPN tunnel actions; there is no 'IPS' action. The action determines whether traffic is permitted or blocked, while IPS inspection is a post-accept processing step applied through security profiles. Choosing 'IPS' as an action would be syntactically impossible and conceptually confusing, as IPS is not a disposition but an inspection capability.

  • ✓

    Create a security profile group containing the IPS profile and apply it to the policy

    Why this is correct

    The correct approach is to create a security profile group that contains the IPS sensor and then apply that group to the firewall policy governing traffic to the web server. This groups the IPS sensor with other inspection profiles, enabling layered UTM inspection on accepted traffic. When the policy action is ACCEPT and the profile group is attached, all matching sessions are inspected by the IPS engine against its configured signatures and rules.

  • ✗

    Configure a VIP for the web server

    Why it's wrong here

    A Virtual IP (VIP) is used for destination NAT, translating an external IP address and port to the internal web server's IP address and port. It does not invoke any security inspection, including IPS, because NAT and UTM inspection are separate functions in the FortiGate processing flow. Configuring only a VIP would allow traffic to reach the server without any IPS protection; you would still need to apply an IPS profile to the corresponding firewall policy.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.