Courseiva
Security Profiles →mediumMultiple Select

NSE4 Security Profiles Practice Question

A FortiGate administrator is configuring intrusion prevention (IPS) for a web server. The administrator wants to both block known exploits and detect anomalous traffic patterns. Which TWO features should be enabled? (Choose two.)

⚠ Common exam trap

Candidates often confuse 'anomaly detection' with 'application control' or 'web filter', thinking those features also detect unusual traffic patterns, but anomaly detection is a distinct IPS sub-feature for behavioral analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IPS signatures

IPS signatures (A) are correct because they contain predefined patterns of known exploits, allowing the FortiGate to match and block malicious traffic against a web server. Anomaly detection (D) is correct because it establishes a baseline of normal traffic and alerts on deviations, enabling detection of zero-day or unusual patterns that signatures may miss.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    IPS signatures

    Why this is correct

    IPS signatures are the core of intrusion prevention: the FortiGate inspector compares each packet's payload and header fields against a database of known exploit patterns and CVE-based indicators. This allows the device to match, log, and drop malicious traffic in real time, flagging only packets that precisely match a recognized attack signature. It is the only option here that actively inspects for exploit content, so it directly addresses the administrator's goal of blocking intrusion attempts.

  • ✗

    Web filter

    Why it's wrong here

    Web filtering is URL-level classification and policy enforcement: the FortiGate uses categories and reputation scores to allow, block, or warn based on the destination website. It examines only the requested URL or IP, not the data packets traveling over that connection, so it cannot see or block exploit code hidden in the payload. This makes web filtering a great tool for web-access control, but it is not an intrusion prevention mechanism.

  • ✗

    Antivirus

    Why it's wrong here

    Antivirus scanning inspects files for malware using signature and heuristic detection at the application layer, such as scanning attachments in HTTP, SMTP, or FTP traffic. It focuses on binary or document-based threats and cannot analyze the broader network flow for exploit attempts, like a buffer overflow over a raw TCP connection. Because intrusion prevention requires network-level pattern and behavioral analysis, antivirus is a separate, complementary tool, not the solution for IPS.

  • ✓

    Anomaly detection

    Why this is correct

    Anomaly detection uses baseline learning and statistical analysis to identify traffic patterns that deviate from normal behavior, such as SYN floods, distributed port scans, or unusual data exfiltration. Unlike signatures that match known threats, anomaly detection can spot zero-day or obfuscated attacks by noticing a deviation in traffic volume, rate, or protocol structure. It works alongside signature-based IPS in FortiGate, though its effectiveness depends on an accurate normal baseline and can produce false positives if not tuned.

  • ✗

    Application control

    Why it's wrong here

    Application control identifies and classifies network traffic by application using protocol fingerprints and heuristics, enabling policies to block or prioritize apps like social media, torrents, or VoIP. It inspects the interaction patterns of an application (e.g., connection methods, handshakes) but does not look for malicious exploit payloads or abnormal network behavior. Thus it is a traffic management feature, not a security detection mechanism for intrusions, which is why it is incorrect here.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.