Courseiva
Security Profiles →mediumMultiple Choice

NSE4 Security Profiles Practice Question

A network administrator notices that users can access websites categorized as 'Pornography' despite a web filter profile blocking that category. The firewall policy uses the web filter profile and is applied to the users' traffic. What is the MOST likely cause?

⚠ Common exam trap

Many candidates assume the web filter profile is misapplied or that users are bypassing the firewall, but the real issue is typically a connectivity failure to FortiGuard servers, which causes the filter to default to allowing unrated or uncategorized sites.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The FortiGate cannot reach the FortiGuard servers

The most likely cause is that the FortiGate cannot reach the FortiGuard servers. Web filter profiles rely on FortiGuard's cloud-based URL categorization to block categories like 'Pornography'. If the FortiGate loses connectivity to the FortiGuard servers (e.g., due to firewall rules, DNS issues, or proxy settings), it cannot retrieve the category rating for requested URLs, and the default action (often 'allow' if not explicitly set to block) will permit the traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The FortiGate cannot reach the FortiGuard servers

    Why this is correct

    When the FortiGate cannot reach the FortiGuard servers, web filtering cannot obtain real-time URL category ratings. In FortiOS, unrated or unknown URLs are treated as 'unrated' by default, and the default action for unrated URLs is 'allow' (fail-open). This means every visited website becomes accessible regardless of the web filter profile's block rules, because the firewall has no data to classify the site. The administrator should verify FortiGuard connectivity via `diagnose webfilter fortiguard-status` and confirm that outbound HTTPS (TCP/443) to FortiGuard servers is not being blocked by an upstream firewall or NAT policy.

  • ✗

    The web filter profile is applied to the wrong policy

    Why it's wrong here

    If the web filter profile were bound to the wrong firewall policy, only the traffic traversing that specific policy would be affected, leaving other policies unfiltered. The administrator has already confirmed the correct policy is in use, so this is not the cause. Additionally, a wrong-policy misconfiguration would likely show inconsistent filtering behavior across different source users or destinations, not a complete absence of filtering for all users. Because the problem affects all users globally, a policy-binding error at a single point cannot explain the widespread failure.

  • ✗

    The users are bypassing the FortiGate using a proxy

    Why it's wrong here

    Users could theoretically bypass the FortiGate by using an explicit client-side proxy or a SOCKS proxy that tunnels traffic outside the firewall's inspection path, but this would require deliberate client configuration and would not affect an entire user base without administrative deployment. Even if a proxy were in use, it would produce symptoms where some users (the proxy users) have unrestricted access while others are filtered, not a uniform fail-open condition for everyone. The more parsimonious explanation is a FortiGuard connectivity failure, which stops filtering for all traffic simultaneously without requiring any user action.

  • ✗

    The web filter profile has the 'Override' feature enabled

    Why it's wrong here

    The Override feature in FortiOS web filtering lets administrators create custom exceptions for specific URL categories or individual sites, often using an external connector or manual override rules. Enabling Override does not automatically allow all categories; it only applies to the exact URLs or categories for which an override is defined, and it requires prior administrative configuration. Since this is an enterprise-wide issue affecting all users, a single override rule limited to certain sites could not cause all websites to become accessible, nor would it be enabled accidentally without a clear administrative intent.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.