NSE4 Security Profiles Practice Question
A FortiGate administrator wants to ensure that all DNS queries to known malware domains are blocked. The firewall policy allows DNS traffic. Which security profile must be applied?
⚠ Common exam trap
The trap is choosing web filter because it also deals with 'domains' — but web filter inspects HTTP URLs, while DNS filter inspects the DNS query itself, which is the correct layer for blocking malware domain lookups.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS filter profile
To block DNS queries to known malware domains, the FortiGate must apply a DNS filter profile to the firewall policy that allows DNS traffic. The DNS filter profile uses FortiGuard's DNS threat database to block or redirect queries to malicious domains, botnets, and phishing sites. This is the purpose-built profile for DNS-layer protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Web filter profile
Why it's wrong here
Web filter profiles inspect HTTP and HTTPS traffic for URL categories and content, not the DNS protocol itself. Because DNS queries occur before any HTTP request, a web filter cannot see or block the initial domain resolution. Even if a malicious domain is later blocked during a web request, the DNS query itself remains unfiltered, leaving other services (e.g., FTP, email) vulnerable. Thus, a web filter alone cannot ensure all DNS queries are protected.
- ✓
DNS filter profile
Why this is correct
A DNS filter profile is the correct control because it specifically inspects DNS queries and applies FortiGuard threat intelligence to block malicious, botnet, or phishing domains at the resolution stage. It can also enforce safe search and sinkhole domains, preventing clients from reaching known bad destinations even if they use custom DNS servers. By operating at the DNS layer, it protects all protocols and applications that rely on name resolution, providing comprehensive, early defense.
- ✗
Antivirus profile
Why it's wrong here
Antivirus profiles scan files, emails, and web content for malware signatures and heuristics, but they do not parse DNS protocol messages. DNS queries are small, non-executable packets that carry only domain names, so signature-based scanning has nothing to inspect. Moreover, antivirus cannot evaluate the reputation of a queried domain or apply domain category policies. Therefore, an antivirus profile is irrelevant to DNS query filtering.
- ✗
Application control profile
Why it's wrong here
Application control profiles identify and manage applications based on traffic signatures, heuristics, and behavioral patterns, such as recognizing social media or streaming services. DNS queries are not applications themselves but a protocol used to resolve domain names, and application control may only flag DNS as a generic service without analyzing the specific domains. It cannot block or allow individual domains based on threat intelligence or category. Hence, application control is unsuitable for DNS filtering.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.