NSE4 Security Profiles Practice Question
A network administrator notices that a FortiGate IPS sensor is not detecting any attacks, even though there is known malicious traffic on the network. Which initial troubleshooting step should the administrator take?
⚠ Common exam trap
The trap here is that candidates often jump to changing inspection modes or firewall policies, forgetting that the IPS engine must be running and signatures current for any detection to occur, which is the most basic and critical prerequisite.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the IPS engine is running and signatures are up to date.
The first step in troubleshooting a non-functional IPS sensor is to verify that the IPS engine is running and that the IPS signatures are up to date. If the engine is stopped or signatures are outdated, the sensor cannot detect known malicious traffic regardless of other configurations. This foundational check ensures the detection mechanism itself is operational before investigating policy or mode settings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ensure the firewall policy is set to flow-based inspection.
Why it's wrong here
IPS is fully supported in both flow-based and proxy-based inspection modes; the selected mode only affects how traffic is processed (single-pass versus full proxy) and does not enable or disable the IPS engine itself. Switching to flow-based inspection would not repair a stopped IPS engine or an outdated signature database, so this action is not a valid diagnostic step.
- ✗
Disable any DoS policies that might be blocking traffic.
Why it's wrong here
DoS policies are independent of IPS sensors: they enforce rate-based and anomaly-based thresholds to mitigate floods, while IPS sensors match known signatures and protocol anomalies. If the IPS engine is down or signatures are stale, disabling a DoS policy will not cause the IPS sensor to detect threats because the two features use completely different detection mechanisms and are evaluated separately in the FortiGate traffic pipeline.
- ✓
Verify that the IPS engine is running and signatures are up to date.
Why this is correct
The IPS engine (ipsengine) is the process that actually inspects packets against the signature database; if it is not running or has crashed, no IPS detection can occur. Additionally, the FortiGuard IPS package must be current, as outdated signatures will fail to match recently disclosed vulnerabilities. Running the command 'get ips status' verifies engine status and signature version, and 'execute update now' forces an update, making this the correct and direct remedy.
- ✗
Check that the FortiGate is configured in NAT mode.
Why it's wrong here
IPS functionality is available in both NAT and transparent operation modes; NAT mode only controls source/destination address translation and does not affect packet inspection or signature matching. Checking the operation mode is therefore unrelated to an IPS sensor's failure to detect attacks, and changing to NAT mode would not restore IPS engine operation or refresh outdated signature updates.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.