A network administrator notices that HTTP traffic to a specific website is being blocked by the web filter profile, but the website is categorized as 'General – Personal' in FortiGuard, which is allowed. What could cause this block?
URL filter entries are local, rule-based patterns evaluated before FortiGuard category lookup. If a block entry matches the specific domain or URL, the session is dropped immediately, regardless of the category's default action. This is why a single website can be blocked while other sites in the same FortiGuard category remain accessible, as described in the scenario.
Why this answer
A URL filter entry can explicitly block a specific website regardless of its FortiGuard category. Even if the category 'General – Personal' is allowed in the web filter profile, a more specific URL filter rule with a higher priority (lower order number) can override the category-based action. This is a common scenario where an administrator creates a custom URL block for a particular domain or URL pattern, which takes precedence over the FortiGuard category lookup.
Exam trap
The trap here is that candidates often assume the FortiGuard category is the sole determinant of web access, forgetting that URL filter entries have higher precedence and can block individual sites even when their category is permitted.
How to eliminate wrong answers
Option A is wrong because a FortiGuard category override would change the category assigned to the website, but if the override incorrectly set it to a blocked category, the traffic would be blocked for that reason—however, the question states the category is allowed, so an override would not cause a block unless it changed the category to a blocked one, which is not indicated. Option B is wrong because antivirus profiles inspect file downloads and HTTP content for malware, not the initial HTTP request to a website; they would not block the website itself unless a virus was detected in a downloaded file, which is not mentioned. Option D is wrong because DNS filter blocks domains at the DNS query level, preventing resolution entirely, but the question indicates HTTP traffic is blocked, implying the DNS query succeeded and the TCP connection was attempted, so a DNS filter block would manifest as a DNS resolution failure, not an HTTP block.