Courseiva

NSE4 System and Network Administration Practice Question

A FortiGate administrator needs to ensure that all DNS queries from internal clients are forwarded to a specific DNS server for security filtering. Which configuration should be applied?

⚠ Common exam trap

Many exam-takers confuse DNS forwarding with policy routing or firewall policies, assuming traffic redirection requires explicit routing or allow rules, rather than understanding that DNS forwarding is a dedicated application-layer relay feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable DNS forwarding under Network > DNS and set the system DNS to the desired server

DNS forwarding on FortiGate allows the device to act as a DNS relay, intercepting DNS queries from internal clients and forwarding them to a specified DNS server for security filtering. This is configured under Network > DNS by setting the system DNS to the desired server, which ensures all DNS traffic is redirected without requiring policy routing or firewall rule changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use policy routing to redirect DNS traffic to the server

    Why it's wrong here

    Policy routing operates at the packet-forwarding layer and can steer DNS traffic toward a specific IP, but it only changes the next hop for selected sessions. It does not make the FortiGate act as a DNS proxy or resolver, nor does it configure the FortiGate to receive DNS queries from clients on its own interface. Even if you redirect outbound DNS packets, clients would still be sending directly to whatever server is selected, and the FortiGate would not be able to cache or apply DNS forwarding policies. DNS forwarding is the feature specifically designed to accept client queries on the FortiGate and resolve them using configured upstream servers.

  • ✗

    Create a firewall policy to allow DNS traffic to the external server only

    Why it's wrong here

    A firewall policy can restrict which DNS servers are reachable, but it cannot force clients to send their queries to the FortiGate in the first place. If the policy allows only traffic to the external DNS server, clients can still query that server directly, bypassing the FortiGate entirely. The administrator needs the FortiGate to intercept and forward DNS requests, which requires enabling DNS forwarding so that the FortiGate listens on its own interface for DNS queries and then relays them to the designated system DNS servers. A firewall policy alone solves only the filtering aspect, not the forwarding or centralization requirement.

  • ✓

    Enable DNS forwarding under Network > DNS and set the system DNS to the desired server

    Why this is correct

    Enabling DNS forwarding under Network > DNS configures the FortiGate to accept DNS queries sent to its interface IP and then forward them to the system DNS servers, which you set to the desired server. This makes the FortiGate act as a DNS proxy or forwarder, ensuring that all clients that use the FortiGate as their DNS server have their queries resolved by the specified upstream server. It also provides the benefit of caching DNS responses. This is the correct and intended feature for this scenario because it directly addresses the need to centralize and control DNS resolution.

  • ✗

    Configure a DNS database on the FortiGate

    Why it's wrong here

    A DNS database on the FortiGate is used to host authoritative DNS zones, such as for internal domain records or split-horizon DNS, where the FortiGate serves answers directly from its own database. It does not forward queries to an upstream DNS server, and it does not change how client DNS requests are handled unless a matching zone exists. Configuring a DNS database would only affect queries for domains that the FortiGate is authoritative for; all other queries would still be resolved using the normal system DNS settings without any forwarding or interception behavior. This option is irrelevant to forwarding client DNS queries to a specific external server.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.