NSE4 System and Network Administration Practice Question
A FortiGate administrator needs to ensure that all DNS queries from internal clients are forwarded to a specific DNS server for security filtering. Which configuration should be applied?
⚠ Common exam trap
Many exam-takers confuse DNS forwarding with policy routing or firewall policies, assuming traffic redirection requires explicit routing or allow rules, rather than understanding that DNS forwarding is a dedicated application-layer relay feature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable DNS forwarding under Network > DNS and set the system DNS to the desired server
DNS forwarding on FortiGate allows the device to act as a DNS relay, intercepting DNS queries from internal clients and forwarding them to a specified DNS server for security filtering. This is configured under Network > DNS by setting the system DNS to the desired server, which ensures all DNS traffic is redirected without requiring policy routing or firewall rule changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use policy routing to redirect DNS traffic to the server
Why it's wrong here
Policy routing operates at the packet-forwarding layer and can steer DNS traffic toward a specific IP, but it only changes the next hop for selected sessions. It does not make the FortiGate act as a DNS proxy or resolver, nor does it configure the FortiGate to receive DNS queries from clients on its own interface. Even if you redirect outbound DNS packets, clients would still be sending directly to whatever server is selected, and the FortiGate would not be able to cache or apply DNS forwarding policies. DNS forwarding is the feature specifically designed to accept client queries on the FortiGate and resolve them using configured upstream servers.
- ✗
Create a firewall policy to allow DNS traffic to the external server only
Why it's wrong here
A firewall policy can restrict which DNS servers are reachable, but it cannot force clients to send their queries to the FortiGate in the first place. If the policy allows only traffic to the external DNS server, clients can still query that server directly, bypassing the FortiGate entirely. The administrator needs the FortiGate to intercept and forward DNS requests, which requires enabling DNS forwarding so that the FortiGate listens on its own interface for DNS queries and then relays them to the designated system DNS servers. A firewall policy alone solves only the filtering aspect, not the forwarding or centralization requirement.
- ✓
Enable DNS forwarding under Network > DNS and set the system DNS to the desired server
Why this is correct
Enabling DNS forwarding under Network > DNS configures the FortiGate to accept DNS queries sent to its interface IP and then forward them to the system DNS servers, which you set to the desired server. This makes the FortiGate act as a DNS proxy or forwarder, ensuring that all clients that use the FortiGate as their DNS server have their queries resolved by the specified upstream server. It also provides the benefit of caching DNS responses. This is the correct and intended feature for this scenario because it directly addresses the need to centralize and control DNS resolution.
- ✗
Configure a DNS database on the FortiGate
Why it's wrong here
A DNS database on the FortiGate is used to host authoritative DNS zones, such as for internal domain records or split-horizon DNS, where the FortiGate serves answers directly from its own database. It does not forward queries to an upstream DNS server, and it does not change how client DNS requests are handled unless a matching zone exists. Configuring a DNS database would only affect queries for domains that the FortiGate is authoritative for; all other queries would still be resolved using the normal system DNS settings without any forwarding or interception behavior. This option is irrelevant to forwarding client DNS queries to a specific external server.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.