NSE4 Security Profiles Practice Question
A FortiGate administrator is configuring intrusion prevention (IPS) for a web server. The administrator wants to both block known exploits and detect anomalous traffic patterns. Which TWO features should be enabled? (Choose two.)
⚠ Common exam trap
Candidates often confuse 'anomaly detection' with 'application control' or 'web filter', thinking those features also detect unusual traffic patterns, but anomaly detection is a distinct IPS sub-feature for behavioral analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IPS signatures
IPS signatures (A) are correct because they contain predefined patterns of known exploits, allowing the FortiGate to match and block malicious traffic against a web server. Anomaly detection (D) is correct because it establishes a baseline of normal traffic and alerts on deviations, enabling detection of zero-day or unusual patterns that signatures may miss.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IPS signatures
Why this is correct
IPS signatures are the core of intrusion prevention: the FortiGate inspector compares each packet's payload and header fields against a database of known exploit patterns and CVE-based indicators. This allows the device to match, log, and drop malicious traffic in real time, flagging only packets that precisely match a recognized attack signature. It is the only option here that actively inspects for exploit content, so it directly addresses the administrator's goal of blocking intrusion attempts.
- ✗
Web filter
Why it's wrong here
Web filtering is URL-level classification and policy enforcement: the FortiGate uses categories and reputation scores to allow, block, or warn based on the destination website. It examines only the requested URL or IP, not the data packets traveling over that connection, so it cannot see or block exploit code hidden in the payload. This makes web filtering a great tool for web-access control, but it is not an intrusion prevention mechanism.
- ✗
Antivirus
Why it's wrong here
Antivirus scanning inspects files for malware using signature and heuristic detection at the application layer, such as scanning attachments in HTTP, SMTP, or FTP traffic. It focuses on binary or document-based threats and cannot analyze the broader network flow for exploit attempts, like a buffer overflow over a raw TCP connection. Because intrusion prevention requires network-level pattern and behavioral analysis, antivirus is a separate, complementary tool, not the solution for IPS.
- ✓
Anomaly detection
Why this is correct
Anomaly detection uses baseline learning and statistical analysis to identify traffic patterns that deviate from normal behavior, such as SYN floods, distributed port scans, or unusual data exfiltration. Unlike signatures that match known threats, anomaly detection can spot zero-day or obfuscated attacks by noticing a deviation in traffic volume, rate, or protocol structure. It works alongside signature-based IPS in FortiGate, though its effectiveness depends on an accurate normal baseline and can produce false positives if not tuned.
- ✗
Application control
Why it's wrong here
Application control identifies and classifies network traffic by application using protocol fingerprints and heuristics, enabling policies to block or prioritize apps like social media, torrents, or VoIP. It inspects the interaction patterns of an application (e.g., connection methods, handshakes) but does not look for malicious exploit payloads or abnormal network behavior. Thus it is a traffic management feature, not a security detection mechanism for intrusions, which is why it is incorrect here.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.