Courseiva
Security Profiles →easyMultiple Choice

NSE4 Security Profiles Practice Question

A FortiGate administrator wants to block all traffic to websites that are categorized as 'Malware' and 'Phishing'. Which security profile should be configured to achieve this goal?

⚠ Common exam trap

NSE4 often tests the distinction between Web Filter (URL categories) and DNS Filter (DNS-based blocking) — candidates may choose DNS Filter thinking it blocks malware sites, but it does not use the same category database.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Web Filter profile

A Web Filter profile on FortiGate is used to block or allow traffic based on website categories, including 'Malware' and 'Phishing'. It leverages FortiGuard category-based filtering to inspect HTTP/HTTPS traffic and apply actions (block, allow, monitor) per category, making it the correct profile to block those specific website categories.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS Filter profile

    Why it's wrong here

    A DNS Filter profile operates at the DNS query layer, using FortiGuard's domain reputation database to block resolution of known malicious FQDNs. However, it does not inspect HTTP/HTTPS URLs or categorize web content, so it cannot enforce a block on an entire URL category such as Malware or Phishing. Even if a domain is allowed by DNS filtering, the actual web request might still be malicious or belong to a blocked category, making this the wrong tool for category-based web blocking.

  • ✓

    Web Filter profile

    Why this is correct

    A Web Filter profile is the correct mechanism because it applies FortiGuard URL category classification directly to HTTP/HTTPS traffic in the firewall policy. By referencing categories such as Malware and Phishing, the profile can immediately block all sessions to sites in those categories, regardless of the actual IP address, and it supports exemptions and overrides. The profile also integrates with antivirus inspection and SSL deep inspection for encrypted traffic, providing a holistic web access control.

  • ✗

    IPS profile

    Why it's wrong here

    An IPS profile is designed to detect and prevent network exploits, trojans, and vulnerability attempts using rule-based signatures, not to classify or block URL categories. While it might occasionally flag a malicious web download, it does not maintain a URL category database, nor does it inspect the semantic content of a web page to determine if it belongs to a policy-defined category. Using IPS for this purpose would be misapplied and ineffective for blocking all traffic to a specific web category.

  • ✗

    Application Control profile

    Why it's wrong here

    An Application Control profile identifies and controls applications based on App Control signatures, such as SSL, HTTP, or specific proprietary protocols, rather than URL categories. It can block an entire application like a web browser, but that would stop all web access indiscriminately, not just the categories you want (e.g., Malware or Phishing). Additionally, Application Control does not parse URLs or use FortiGuard URL classification, so it lacks the granular, category-specific blocking capability of a Web Filter profile.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator configures a web filter profile to block the URL category 'Pornography'. The profile is applied to a policy for the sales department. Users report they can still access some sites that should be blocked. The administrator verifies that the FortiGuard web filter service is licensed and the FortiGate has internet connectivity. What should the administrator check next?

hard
  • A.Verify that the antivirus profile is not interfering with web filtering.
  • ✓ B.Ensure the web filter profile has 'FortiGuard category based filter' enabled and the action for 'Pornography' is set to 'Block'.
  • C.Check if the sales department policy is using NAT that might bypass the FortiGate.
  • D.Confirm that the FortiGate has a static route to the FortiGuard servers.

Why B: In FortiOS, a web filter profile only enforces FortiGuard category blocking if the 'FortiGuard category based filter' toggle is enabled within the profile and the specific category (e.g., Pornography) has its action set to 'Block'. If the toggle is off, or the category action is left at 'Allow' or 'Monitor', the profile will not block those sites even though the FortiGuard license is valid and connectivity is fine. This is the most common misconfiguration when categories appear to be ignored.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.