NSE4 Security Profiles Practice Question
A FortiGate administrator wants to block access to a list of known malicious websites. The list is updated frequently by a third-party threat intelligence feed. Which FortiGate feature should the administrator use to dynamically block these sites without manual intervention?
⚠ Common exam trap
Watch out — candidates often confuse FortiGuard categories with external threat feeds; FortiGuard is Fortinet-maintained, while external feeds are third-party and require a connector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
External threat feed connector
External threat feed connectors enable the FortiGate to ingest blocklists from external sources and use them in policies. They support automatic updates, so the administrator does not need to manually maintain the list. This is the correct feature for dynamically blocking sites from a third-party threat intelligence feed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Static URL filter
Why it's wrong here
Static URL filter requires manual entry of each URL or pattern. It does not automatically update from external threat feeds. The administrator would need to edit the filter each time the list changes, which is not dynamic and does not meet the requirement for automatic updates.
- ✓
External threat feed connector
Why this is correct
External threat feed connectors allow the FortiGate to subscribe to external feeds and automatically update blocklists. These can be used in firewall policies or web filter profiles to block malicious sites. This provides dynamic, automatic updates without manual intervention, satisfying the requirement.
- ✗
DNS filter
Why it's wrong here
DNS filter can block domains based on FortiGuard categories or static entries, but it does not natively subscribe to external threat feeds for dynamic updates. While it can block malicious domains, it requires manual configuration or relies on FortiGuard, not third-party feeds.
- ✗
FortiGuard web filter category
Why it's wrong here
FortiGuard web filter categories are maintained by Fortinet and updated automatically, but they do not incorporate arbitrary third-party threat intelligence feeds. The administrator cannot add a custom external feed to a FortiGuard category. Thus it does not meet the requirement for using a specific third-party feed.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.