NSE4 Security Profiles Practice Question
A network administrator wants to ensure that all users are blocked from accessing websites categorized as 'Pornography' and 'Hacking' on a FortiGate. Which TWO actions should the administrator take? (Choose two.)
⚠ Common exam trap
Candidates often confuse URL filtering (pattern-based) with web filter category blocking (category-based), or assume SSL deep inspection is mandatory for category-based blocking when it is not required for domain-level categorization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply the web filter profile to the firewall policy that governs outbound internet traffic
A web filter profile must be applied to a firewall policy to enforce web filtering on outbound internet traffic. Without this association, the profile's settings (including category blocks) are not activated. The firewall policy is the enforcement point where security profiles are linked to traffic flows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a URL filter to block all URLs containing 'pornography' and 'hacking'
Why it's wrong here
A URL filter in FortiGate is designed to match user-defined strings or patterns in the URL itself, such as '/pornography' or '/hacking', not the FortiGuard web category database. Relying on keyword matching would require manually enumerating thousands of individual URLs and still miss sites whose domain or path contains no literal matching string but are nonetheless categorized as pornographic or hacking. This approach is inefficient, incomplete, and does not leverage the dynamic, cloud-updated FortiGuard categories that provide comprehensive coverage across the entire category.
- ✗
Enable DNS filter and block the categories there
Why it's wrong here
DNS filtering is a separate feature that applies to DNS queries, not to HTTP/HTTPS traffic passing through the firewall policy. Even if a domain is blocked at the DNS level, a user could bypass it by using a direct IP address, a cached DNS record, or an alternate resolver, so it does not reliably block access at the application layer. The requirement is to block access in the firewall policy governing outbound traffic, and that requires a web filter profile, not a DNS filter profile.
- ✓
Apply the web filter profile to the firewall policy that governs outbound internet traffic
Why this is correct
Applying the web filter profile to the firewall policy that governs outbound internet traffic ensures that HTTP/HTTPS requests from internal users are inspected against the configured URL categories before the traffic is allowed to pass. This satisfies the stem’s constraint that all users must be blocked from accessing 'Pornography' and 'Hacking' sites, as the profile is enforced at the point where traffic exits the internal network to the internet.
- ✗
Enable SSL deep inspection to ensure the categories can be identified
Why it's wrong here
SSL deep inspection is a traffic decryption capability, not a category enforcement mechanism. FortiGuard categories are assigned based on URL reputation and domain analysis, and the FortiGate can often determine the category from the TLS SNI or certificate even without full deep inspection. Enabling deep inspection alone does not create a policy that blocks 'Pornography' or 'Hacking' categories; you still must configure a web filter profile with block actions and attach it to the outbound firewall policy for the blocking to take effect.
- ✓
Create a web filter profile and set the categories 'Pornography' and 'Hacking' to 'block'
Why this is correct
Creating a web filter profile allows you to select FortiGuard categories and assign explicit actions — such as 'Block' — for 'Pornography' and 'Hacking'. The profile is then applied to the firewall policy governing outbound internet traffic, which is the enforcement point where every internal user's HTTP/HTTPS request is evaluated against that category list before being allowed out. This direct, category-based approach provides comprehensive and centrally managed protection for all users, making it the correct solution.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.