Courseiva
Security Profiles →hardMultiple Choice

NSE4 Security Profiles Practice Question

A security administrator is configuring an IPS sensor on a FortiGate to protect a web server. The sensor includes a signature that detects a specific HTTP exploit. The administrator wants to ensure that the signature blocks the attack but also generates a log entry for each detection. Which action should be taken for that signature in the IPS sensor?

⚠ Common exam trap

Many exam-takers confuse 'Packet Logging' with standard event logging; packet logging captures raw packets for deep analysis, while standard logging records the event details.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the action to 'Block' and enable 'Logging' for the signature.

In a FortiGate IPS sensor, the 'Block' action drops packets matching the signature, preventing the exploit from reaching the server. Enabling 'Logging' for that signature ensures an event is recorded each time the signature is triggered. This combination satisfies both the blocking and logging requirements without unnecessary packet capture or connection resets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the action to 'Reset' and enable 'Logging'.

    Why it's wrong here

    The 'Reset' action sends a TCP RST to terminate the connection, which may block the attack but can also disrupt legitimate traffic if the signature triggers falsely. While 'Logging' would record the event, the 'Reset' action is more aggressive than 'Block' and not necessary for simply blocking the exploit. The requirement is to block, not reset.

  • ✗

    Set the action to 'Monitor' and enable 'Packet Logging'.

    Why it's wrong here

    'Monitor' action only logs the event without blocking the traffic, which fails to stop the exploit. 'Packet Logging' captures packet payloads but does not block. This option would allow the attack to proceed, violating the requirement to block the attack while logging.

  • ✓

    Set the action to 'Block' and enable 'Logging' for the signature.

    Why this is correct

    In a FortiGate IPS sensor, each signature can be configured with an action and logging. Setting the action to 'Block' drops the matching traffic, and enabling logging ensures an event is recorded. This directly meets the requirement to block the attack and generate a log entry for each detection.

  • ✗

    Set the action to 'Block' and enable 'Packet Logging'.

    Why it's wrong here

    Setting the action to 'Block' correctly blocks the attack, but 'Packet Logging' captures the full packet for forensic analysis, which is not the same as generating a standard log entry for each detection. Packet logging can be resource-intensive and is typically used for troubleshooting, not for routine logging of IPS events.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.