Courseiva
Security Profiles →mediumMultiple Choice

NSE4 Security Profiles Practice Question

An administrator configures an IPS profile to block SQL injection attacks. However, SQL injection traffic is still passing through the FortiGate. The administrator confirms the IPS profile is applied to the correct policy. What is the most likely reason?

⚠ Common exam trap

Many candidates assume applying an IPS profile automatically blocks all attacks, but they overlook that individual signatures within the profile must be explicitly enabled and set to 'block' for the desired attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IPS signatures for SQL injection are disabled in the profile

IPS profiles in FortiGate consist of a set of IPS signatures that can be individually enabled or disabled. If the administrator configured an IPS profile to block SQL injection attacks but the specific SQL injection signatures are disabled within that profile, the FortiGate will not inspect or block that traffic, even if the profile is correctly applied to the policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The firewall policy is in proxy-based mode

    Why it's wrong here

    In FortiOS, IPS is supported in both flow-based and proxy-based firewall policies, and the policy mode does not determine whether IPS can block SQL injection. In fact, proxy-based inspection reassembles traffic before applying IPS, which can improve detection accuracy for certain threats. Choosing proxy mode would not cause a SQL injection attack to pass; the IPS sensor would still evaluate the traffic. Therefore, this is not the likely reason the attack is not blocked.

  • ✗

    The IPS profile is configured for anomaly detection only

    Why it's wrong here

    An anomaly-based IPS profile monitors traffic for behavioral deviations, but SQL injection is a known signature-based attack that requires matching against IPS signatures. Simply enabling anomaly detection does not disable signature matching; the profile would still process any enabled signatures unless they were explicitly turned off. If the profile were truly 'anomaly only,' then no signatures would be active, which could explain the behavior, but the more precise and common cause is that the specific SQL injection signatures are disabled. This option is wrong because it misidentifies the detection mechanism as the root issue rather than the signature configuration.

  • ✓

    IPS signatures for SQL injection are disabled in the profile

    Why this is correct

    IPS in FortiGate detects SQL injection by matching traffic against a set of pre-defined signatures in the IPS database. If the administrator has not enabled those signatures in the IPS profile, or has set them to 'pass' rather than 'block,' the attack traffic will be allowed through even though the IPS profile is applied to the policy. Each signature in FortiOS has an individual action (allow, monitor, block) that can be overridden, so the most direct reason a SQL injection would not be blocked is that the corresponding signatures are disabled or set to pass. This is the correct answer because it precisely identifies the signature-level configuration as the cause.

  • ✗

    Deep inspection is required for IPS to work

    Why it's wrong here

    Deep inspection is only required to decrypt and inspect encrypted traffic such as HTTPS; it is not a prerequisite for IPS to work on plaintext traffic. SQL injection attacks are typically sent in HTTP GET or POST requests over port 80, which can be inspected by IPS without deep inspection in both flow and proxy modes. If the traffic were encrypted, deep inspection would be necessary, but the scenario does not indicate that. Therefore, saying deep inspection is required for all IPS operation is incorrect; it is only needed to see the application layer inside a TLS tunnel.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.