NSE4 System and Network Administration Practice Question
A FortiGate is deployed at a branch office with a single WAN link. The administrator wants to ensure that the FortiGate itself can resolve external hostnames for features like FortiGuard lookups, but does not want internal clients to use the FortiGate as their DNS server. Which configuration should the administrator apply?
⚠ Common exam trap
The trap here is assuming that configuring DNS servers under System > DNS automatically makes the FortiGate a DNS server for connected clients.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure DNS servers under System > DNS on the FortiGate, and leave the internal interface DNS settings unchanged.
The FortiGate needs its own DNS settings for system lookups, which are configured under System > DNS. This does not affect clients unless the interface DNS server feature is enabled or DHCP hands out the FortiGate as a DNS server. Leaving the internal interface DNS settings unchanged ensures clients continue using their own DNS servers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a DNS filter profile on the outbound firewall policy and set the FortiGate as the primary DNS in the DHCP server.
Why it's wrong here
A DNS filter profile inspects DNS queries but does not provide DNS resolution for the FortiGate itself. Setting the FortiGate as the primary DNS in DHCP would force clients to use it as a DNS server, violating the requirement. This option confuses DNS filtering with DNS client configuration.
- ✓
Configure DNS servers under System > DNS on the FortiGate, and leave the internal interface DNS settings unchanged.
Why this is correct
The System > DNS settings define the DNS servers the FortiGate uses for its own lookups, such as FortiGuard and DNS filtering. This does not enable the FortiGate to answer DNS queries from clients. Internal clients continue using their own DNS servers because the interface DNS settings are not modified.
- ✗
Set the FortiGate as a DNS forwarder under Network > DNS Servers and configure a firewall policy to allow DNS.
Why it's wrong here
There is no Network > DNS Servers menu for DNS forwarding in FortiOS. DNS forwarding is configured via the DNS server settings on an interface, which would make the FortiGate a DNS server for clients. This option misidentifies the GUI location and functionality.
- ✗
Enable DNS server on the internal interface and set the same DNS servers in the DHCP scope.
Why it's wrong here
Enabling DNS server on the internal interface makes the FortiGate listen for and answer DNS queries from clients. This contradicts the requirement that clients must not use the FortiGate as their DNS server. It also adds unnecessary configuration and potential security exposure.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.