Courseiva
Security Profiles →hardMultiple Select

NSE4 Security Profiles Practice Question

An administrator has configured an IPS profile to detect SQL injection attacks. However, some SQL injection attempts are still reaching the web server. Which TWO actions should the administrator take to improve detection?

⚠ Common exam trap

Watch out — candidates often confuse anomaly detection (which is for behavioral baselines) with signature-based detection, or assume that switching inspection modes (flow vs. proxy) fixes detection gaps when the real issue is outdated signatures or missing protocol decoders.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Update the IPS signature database

IPS signatures are the primary mechanism for detecting known SQL injection patterns. If attacks are reaching the web server, the signature database is likely outdated or missing recent attack vectors. Updating the signature database ensures the IPS has the latest patterns to match against SQL injection attempts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure anomaly detection for SQL traffic

    Why it's wrong here

    Anomaly detection in FortiGate IPS uses statistical baselines to identify suspicious behavior, such as an unusual spike in traffic volume or a protocol violation, rather than examining payload content for known attack strings. SQL injection is a content-based threat that manifests as specific payload patterns, like ' OR 1=1, which require signature-based IPS rules to detect reliably. Configuring anomaly detection alone would not inspect those payload patterns, so it would not catch SQL injection; thus, that action is wrong.

  • ✓

    Update the IPS signature database

    Why this is correct

    Updating the FortiGuard IPS signature database is the core step because SQL injection detection depends on signature patterns that recognize specific attack syntax and variations. Signature packages are regularly updated with new and refined rules for recent SQL injection techniques, such as union-based or time-based blind injection. If the database is outdated, the IPS engine lacks those rules, and the policy may silently ignore crafted SQL payloads. Therefore, to detect SQL injection effectively, an administrator must ensure the IPS database is current.

  • ✗

    Disable flow-based inspection and use proxy-based only

    Why it's wrong here

    Flow-based and proxy-based inspection are two alternative modes on FortiGate; IPS can operate in either, and flow-based generally provides adequate signature matching with low latency. Disabling flow-based to force proxy-only is unnecessary and potentially harmful to performance, because it changes the processing path without addressing the detection capability. SQL injection is detected through signature and decoder application, which works in both modes. Thus, making this switch does not improve SQL injection detection and could degrade throughput; it is not a valid corrective action.

  • ✓

    Enable protocol decoders for HTTP and SQL

    Why this is correct

    Protocol decoders in FortiGate IPS parse application-layer protocols like HTTP and SQL, allowing the engine to see through encoding, compression, or fragmented transmission and correctly match signatures. For SQL injection, the HTTP decoder normalizes request headers and parameters, while the SQL decoder interprets the query structure so that malicious SQL commands can be identified even if obfuscated. Enabling these decoders is a direct way to increase visibility and detection accuracy for SQL injection. This action is correct because it addresses the traffic context needed for signature matching.

  • ✗

    Enable SSL deep inspection on the policy

    Why it's wrong here

    SSL deep inspection decrypts HTTPS traffic so the IPS can examine the plaintext payload; it is essential if the SQL injection occurs inside a TLS session, but it does not itself detect the attack. Without it, encrypted requests would be opaque to the IPS, but the question does not indicate whether the traffic is encrypted. Moreover, enabling SSL inspection requires configuring CA certificates and can impact performance; it is an additional network-security measure, not a primary step for SQL injection detection. Therefore, it is wrong to assume SSL inspection alone is needed or sufficient; it only matters conditionally.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.