Granular Web Filtering: Allow Blocked Categories per User Group
A FortiGate administrator is troubleshooting an issue where users cannot access a legitimate website that is categorized as 'Pornography' by FortiGuard. The web filter profile is configured to block that category. The administrator wants to allow access for a specific user group without modifying the global web filter profile. What is the BEST approach?
Quick Answer
The answer is to create a separate firewall policy for that user group with a web filter profile that allows the category. This approach is correct because firewall policies in FortiGate are evaluated in order, and a more specific policy for a targeted user group will be matched before a broader policy, allowing you to override the global block without altering the original profile. On the Fortinet NSE 4 exam, this tests your understanding of policy-based granular web filtering versus profile-based exemptions—a common trap is assuming a URL filter exemption within the same profile works, but that exemption applies to all users using that profile, not just the specific group. Remember the memory tip: "Policy first, profile second"—you control access by policy order, not by modifying the shared profile.
⚠ Common exam trap
It's easy for candidates to think a URL filter exemption (Option C) is the easiest fix, but it modifies the global profile and affects all users, whereas a separate policy with a custom profile is the correct per-group solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a separate firewall policy for that user group with a web filter profile that allows the category
It allows the administrator to create a separate firewall policy for the specific user group that uses a web filter profile configured to allow the 'Pornography' category. This approach overrides the global web filter profile for that group without modifying the original profile, leveraging FortiGate's policy-based security profile assignment.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 282-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator receives reports that some internal users can access Facebook despite a web filtering profile that blocks the 'Social Networking' category. The policy is configured with deep inspection. Which THREE checks should the administrator perform to troubleshoot this issue?
hard- ✓ A.Check if the users are using HTTPS and if the SSL inspection profile has an exemption for Facebook
- B.Ensure that the antivirus profile is enabled on the policy
- ✓ C.Check if the users are accessing Facebook via an SSL VPN tunnel that bypasses the policy
- ✓ D.Verify that the web filtering profile is applied to the correct policy and that the policy order is correct
- E.Confirm that the 'Social Networking' category is not set to 'Monitor' instead of 'Block'
Why A: The troubleshooting should focus on three main areas: (A) SSL inspection exemption – if users access Facebook via HTTPS and the SSL inspection profile exempts Facebook traffic, it bypasses the web filter; (C) SSL VPN bypass – traffic through an SSL VPN tunnel may not match the policy if the tunnel interface is not covered; (D) policy application and order – the web filtering profile must be applied to the correct policy and the policy order must be such that this policy is enforced before any conflicting policy. Option E is a valid check, but since the category is already set to 'Block' in the profile, the issue is more likely related to the other three.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.