NSE4 Security Profiles Practice Question
A network administrator notices that some users can access blocked web categories despite a web filter profile applied to the policy. The admin runs 'diagnose debug rating' and sees 'rating not allow' for the category. What is the MOST likely cause?
⚠ Common exam trap
Candidates often assume a 'rating not allow' message means the filter is working correctly for everyone, overlooking the possibility that an override configured within the same profile can selectively permit access for certain users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The web filter profile has an 'override' configured for those users
The 'rating not allow' message in the 'diagnose debug rating' output indicates that the FortiGate's rating engine correctly identified the category as blocked by the web filter profile. However, if an 'override' is configured for specific users or groups, it allows them to bypass the blocked category. This explains why some users can access the site despite the profile blocking it, as the override takes precedence over the profile's default action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The web filter profile has an 'override' configured for those users
Why this is correct
A web filter override is an explicit exemption configured inside the FortiGate profile that lets certain users, groups, or source IPs bypass the FortiGuard rating decision. When an override is in place, the FortiGuard rating may still be evaluated as 'not allow' (blocked), but the override action overrides that result and permits the session. This exactly matches the symptom where only some users, presumably those included in the override rule, can access sites that are otherwise blocked for everyone else.
- ✗
The policy is not using the correct web filter profile
Why it's wrong here
If the FortiGate policy were referencing the wrong web filter profile, the rating decision would reflect the wrong profile's settings—likely a different action such as 'allow' or a different category set. The log entry 'rating not allow' indicates that the profile actually in use is correctly evaluating the site as blocked, so a profile mismatch would not produce a scenario where some users are allowed despite that rating. A profile mismatch would affect all users with the same policy indiscriminately, not just a specific subset.
- ✗
DNS filter is allowing the domain
Why it's wrong here
DNS filtering on FortiGate operates at the DNS resolution layer and can block or allow domain resolution, but it is entirely separate from the FortiGuard web filter rating that occurs during the HTTP/HTTPS request. Even if the DNS filter allows the domain, the web filter profile still evaluates the URL against its categories and blocks if the rating is not allow. Conversely, if DNS filter were blocking, users would not be able to resolve the domain at all, so the symptom of successful access cannot be attributed to DNS filter allowing it—this is a different security layer.
- ✗
The FortiGuard web filter database is outdated
Why it's wrong here
An outdated FortiGuard database can cause sites to be misclassified or unreachable for rating, but it would affect the rating itself—for example, resulting in an 'unrated' category that may be allowed by default. The fact that the log shows 'rating not allow' means the database has correctly identified the site as a blocked category, so the blocking decision is intact. Moreover, a database limitation would impact all users equally, not selectively allow some users, whereas the observed behavior is specific to certain users, pointing to an override rather than database staleness.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 282-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.