Courseiva
Security Profiles →mediumMultiple Select

NSE4 Security Profiles Practice Question

A security administrator wants to ensure that all DNS queries from internal users are filtered to block access to known malicious domains. Which TWO configurations must be applied?

⚠ Common exam trap

NSE4 often tests that DNS filtering requires both a profile and policy application, and candidates may mistakenly think deep inspection or SSL inspection is needed for DNS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply the DNS Filter profile to the firewall policy that allows DNS traffic

Option B is correct because the DNS Filter profile only takes effect when it is attached to the firewall policy that permits the DNS traffic, so applying it to that policy is what actually enforces filtering on users' queries. Option D is correct because the DNS Filter profile itself is the object that defines which domains are blocked (e.g., via FortiGuard category-based filtering or static domain lists), so it must be created before it can be applied. Option A is not required because deep inspection applies to content/AV scanning of traffic, not to DNS query filtering. Option C is incorrect because DNS inspection is not enabled through the SSL/SSH inspection profile; DNS filtering is handled by the DNS Filter profile. Option E is not needed because configuring a DNS server on the FortiGate does not filter or block malicious domains for internal users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable deep inspection on the firewall policy

    Why it's wrong here

    Deep inspection decrypts and inspects SSL/TLS-encrypted sessions, so applying it to a policy would not affect ordinary DNS queries, which are sent in cleartext over UDP or TCP port 53. Since the DNS filter profile already handles DNS-layer inspection, enabling deep inspection adds unnecessary overhead and does not block malicious domains in regular DNS traffic. It would only become relevant if you needed to inspect DNS over HTTPS (DoH) hidden inside TLS sessions.

  • ✓

    Apply the DNS Filter profile to the firewall policy that allows DNS traffic

    Why this is correct

    A DNS filter profile is a set of blocking rules and categories, but it is inert until it is attached to a firewall policy. When the policy matches DNS traffic, FortiGate applies the profile's rules — such as blocking malicious domains — and returns a 'blocked' response to the client. This is the enforcement point that makes DNS filtering actually work for traffic traversing the FortiGate.

  • ✗

    Enable DNS inspection on the SSL/SSH inspection profile

    Why it's wrong here

    The SSL/SSH inspection profile controls whether and how FortiGate decrypts encrypted traffic for deep inspection; it has no DNS filter settings. DNS queries and responses are typically plaintext, so they are inspected by the DNS filter engine, not by the SSL/SSH proxy. There is no 'DNS inspection' toggle in the SSL/SSH inspection profile, so this action would not provide any malicious-domain blocking.

  • ✓

    Create a DNS Filter profile to block malicious domains

    Why this is correct

    Creating a DNS Filter profile is the first required step: it defines the categories, allow/block lists, and actions (e.g., block, monitor) that determine which domains are considered malicious. Without a profile, there is no policy to apply to traffic. However, a profile alone does not filter anything — it must later be attached to the firewall policy that carries DNS traffic to be enforced.

  • ✗

    Configure a DNS server on the FortiGate

    Why it's wrong here

    Configuring a DNS server under System > Network > DNS sets the FortiGate's own DNS servers for resolving external hostnames used by the device itself, such as for FortiGuard updates or NTP. It does not inspect or filter DNS requests from internal clients; client DNS traffic still flows according to the firewall policy. To filter user DNS, you need a DNS filter profile applied to the relevant policy, not a system DNS setting.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.