NSE4 Security Profiles Practice Question
A FortiGate is configured with an IPS profile to detect and block anomalous network behavior. Which THREE types of detection does IPS anomaly detection include? (Choose three.)
⚠ Common exam trap
Watch out — candidates often confuse signature-based detection (Option D) with anomaly detection, but FortiGate explicitly separates these into distinct IPS detection methods, and the question asks specifically for anomaly detection types.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Port scan detection
Port scan detection is a type of anomaly detection in FortiGate's IPS profile that identifies reconnaissance attempts by monitoring for multiple connection attempts to different ports from a single source. This behavior deviates from normal traffic patterns and is flagged as anomalous, allowing the IPS to block potential scanning activity before an attack progresses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Protocol decoding
Why it's wrong here
Protocol decoding is a distinct IPS method that inspects packet fields and protocol state machines against RFC standards to identify violations like malformed headers, illegal flag combinations, or invalid field values. It does not rely on statistical baselines or rate thresholds; instead, it validates traffic against a known normative model. Because the question is asking specifically for anomaly-based detection, protocol decoding is not an example—it is a specification-matching technique, not a behavioral anomaly detection method.
- ✓
Port scan detection
Why this is correct
Port scan detection in FortiGate's IPS is an anomaly-based behavioral technique that tracks the number of unique destination ports or distinct IP addresses contacted by a single source within a defined time window. When this activity exceeds a configured threshold, the IPS flags it as a port scan, even if no individual packet matches a known signature. This is a rate-based or heuristic anomaly detection approach, making it a correct example of the IPS anomaly detection mode.
- ✓
SYN flood detection
Why this is correct
A SYN flood is a classic denial-of-service attack where an attacker sends a high rate of TCP SYN packets and never completes the three-way handshake, exhausting the target's connection queue. FortiGate's anomaly-based IPS monitors the volume of SYN packets per second toward a destination and triggers when it exceeds a defined threshold. Because this detection relies on rate monitoring and deviation from normal traffic baselines, it is correct as an anomaly detection method, not signature matching.
- ✗
Signature-based detection
Why it's wrong here
Signature-based detection uses fixed patterns—such as byte sequences, regular expressions, or MD5 hashes of known exploits—to match against network traffic. This is the traditional IPS method that requires prior knowledge of an attack, whereas anomaly detection learns a baseline of normal behavior and flags statistical or heuristic deviations from that baseline. The question asks for anomaly detection, so signature-based detection is wrong in that context because it relies on explicit attack fingerprints, not unusual traffic patterns.
- ✓
UDP flood detection
Why this is correct
A UDP flood attack generates a high volume of UDP packets—often to random ports—on a target network, overwhelming the host's ability to process them and triggering ICMP port-unreachable replies, which further degrades performance. FortiGate's anomaly-based IPS detects this by counting UDP packets per destination and comparing the rate against a configured threshold. Since it is a rate-based, behavioral detection mechanism, it correctly fits the definition of anomaly detection in IPS profiles.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.