Courseiva
Security Profiles →hardMultiple Select

NSE4 Security Profiles Practice Question

A FortiGate administrator notices that some users can bypass the web filter to access prohibited categories. The web filter profile is applied to the firewall policy. Which TWO actions should the admin take to determine why the filter is being bypassed? (Choose two.)

⚠ Common exam trap

NSE4 often tests the misconception that attaching a web filter profile is sufficient, ignoring that policy match order and SSL deep inspection are required for the filter to actually see and block HTTPS traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check if the firewall policy that the traffic matches has the web filter profile applied

Option B is correct because if the firewall policy that actually matches the user's traffic does not have the web filter profile attached, the filter is never evaluated and users can reach prohibited categories; the admin must confirm the profile is applied on the matching policy, not just on some other policy. Option D is correct because without SSL deep inspection the FortiGate cannot decrypt HTTPS traffic, so it cannot inspect the URL path or content and the web filter is effectively bypassed for HTTPS sites. Option A is not the primary troubleshooting step here since FortiGuard connectivity issues would typically cause rating failures or blocks rather than selective bypass, and the question focuses on why filtering is bypassed. Option C is incorrect because the DNS filter is a separate feature and its absence does not explain why the web filter profile is not blocking traffic. Option E is incorrect because client browser proxy settings are not a FortiGate web filter configuration element and would not be the standard cause of the filter being bypassed in this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ensure that the FortiGate has connectivity to FortiGuard

    Why it's wrong here

    FortiGuard connectivity is a prerequisite for category-based web filtering, but if the FortiGate cannot reach FortiGuard, the typical symptom is that URL categories are unknown or the filter fails closed/open for all users, not a selective bypass for "some users." The bypass described indicates that a specific policy is not applying the web filter profile at all. Even with FortiGuard reachable, a firewall policy lacking the profile will permit traffic without any URL inspection.

  • ✓

    Check if the firewall policy that the traffic matches has the web filter profile applied

    Why this is correct

    In FortiOS, web filtering is enforced only when a web filter profile is explicitly attached to the firewall policy that matches the traffic. If the policy used by the affected users does not have the profile selected, the FortiGate will not inspect URLs and will allow all web traffic, creating a bypass. The administrator should examine the policy's Security Profiles section to confirm the web filter profile is applied. This is the most direct and common cause of a partial web filter bypass.

  • ✗

    Verify that the DNS filter is also applied to the same policy

    Why it's wrong here

    DNS filtering and web filtering are independent security features in FortiOS. DNS filter blocks or redirects based on DNS queries, while web filter inspects the actual HTTP/HTTPS URLs. A missing DNS filter does not weaken web filtering; even without DNS filter, the web filter can still enforce URL categories and block sites. Therefore, checking the DNS filter is irrelevant to diagnosing why users bypass web filtering, as the web filter operates on a separate layer.

  • ✓

    Check if SSL deep inspection is enabled on the policy

    Why this is correct

    Without SSL/TLS deep inspection enabled on the policy, the FortiGate cannot decrypt HTTPS traffic to read the full URL, so it can only rely on SNI or IP addresses for categorization. This means many HTTPS websites can bypass the web filter because the URL path and embedded links are invisible to the FortiGate. To properly filter HTTPS traffic, the policy must have an SSL deep inspection profile applied in addition to the web filter profile. Thus, checking SSL deep inspection is a valid step when investigating web filter bypasses for encrypted traffic.

  • ✗

    Examine the client's browser proxy settings

    Why it's wrong here

    Browser proxy settings are client-side and do not affect how FortiGate inspects traffic that passes through it in a transparent or routed mode. The FortiGate sees all IP packets at the network layer, regardless of whether the browser is configured to use a proxy; unless the FortiGate is deployed as an explicit proxy, proxy settings are irrelevant. Since the question describes users bypassing the firewall's filtering, the issue lies in the FortiGate configuration, not in the client's browser. Therefore, examining proxy settings is not a useful troubleshooting step.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.