NSE4 Security Profiles Practice Question
A network administrator notices that HTTP traffic to a specific website is being blocked by the web filter profile, but the website is categorized as 'General – Personal' in FortiGuard, which is allowed. What could cause this block?
⚠ Common exam trap
Watch out — candidates often assume the FortiGuard category is the sole determinant of web access, forgetting that URL filter entries have higher precedence and can block individual sites even when their category is permitted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A URL filter entry is blocking the specific website
A URL filter entry can explicitly block a specific website regardless of its FortiGuard category. Even if the category 'General – Personal' is allowed in the web filter profile, a more specific URL filter rule with a higher priority (lower order number) can override the category-based action. This is a common scenario where an administrator creates a custom URL block for a particular domain or URL pattern, which takes precedence over the FortiGuard category lookup.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The web filter profile has an incorrect FortiGuard category override
Why it's wrong here
A FortiGuard category override changes the action for an entire category, not for a single website. If the website's category is permitted by default and the override is not explicitly set to block, it cannot be responsible for blocking that URL. Moreover, any category-based override would affect all sites in that category, not a single specific website, which contradicts the symptom described.
- ✗
The antivirus profile is blocking the website
Why it's wrong here
Antivirus profiles in FortiOS inspect file content and block malware downloads, not individual websites by URL or domain. The AV engine cannot make an allow/block decision based on the requested hostname; it only acts after data reaches the FortiGate. If the site simply served HTML, the AV profile would have no basis to block the HTTP request itself, so this is not a plausible cause.
- ✓
A URL filter entry is blocking the specific website
Why this is correct
URL filter entries are local, rule-based patterns evaluated before FortiGuard category lookup. If a block entry matches the specific domain or URL, the session is dropped immediately, regardless of the category's default action. This is why a single website can be blocked while other sites in the same FortiGuard category remain accessible, as described in the scenario.
- ✗
DNS filter is blocking the domain
Why it's wrong here
A DNS filter blocks domains by intercepting DNS queries and dropping the resolution, so the client receives no IP address and the HTTP request never reaches the FortiGate's web filter. If the DNS filter were blocking the domain, the user would see a DNS resolution failure rather than a web-filter block page. The fact that the issue is observed in HTTP traffic to a specific site suggests that the request was successfully routed to the web filter, ruling out DNS filtering as the cause.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 282 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.