NSE4 Security Profiles Practice Question
An administrator is configuring an IPS sensor to protect a web server. The administrator wants to ensure that the IPS blocks attacks targeting the web server, but also wants to minimize false positives. Which two actions should the administrator take when configuring the IPS sensor? (Choose two.)
⚠ Common exam trap
The trap here is thinking that enabling all signatures with block action is the most secure, but it often leads to false positives and network disruption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the action for critical and high severity signatures to 'block'.
To block attacks while minimizing false positives, the administrator should focus on high-severity signatures with block action and apply the IPS sensor only to the relevant traffic. This targeted approach ensures critical threats are stopped without disrupting legitimate traffic. Other options either block everything (causing false positives) or monitor everything (not blocking).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable IPS signature updates and use the 'recommended' action for signatures.
Why it's wrong here
Enabling signature updates is good, but using the 'recommended' action may not consistently block critical attacks; recommended actions can vary and may be monitor for some. It does not explicitly ensure blocking of high-severity attacks. This option alone does not guarantee the desired blocking behavior.
- ✗
Set the action for all signatures to 'monitor' to avoid false positives.
Why it's wrong here
Setting all signatures to monitor would not block any attacks; it would only log them. This fails to protect the web server. While it avoids false positives, it does not meet the requirement to block attacks. The administrator needs a balance, not just monitoring.
- ✓
Set the action for critical and high severity signatures to 'block'.
Why this is correct
Setting critical and high severity signatures to block ensures that the most dangerous attacks are stopped. These signatures are typically well-tested and have low false positive rates. This balances security with minimizing false positives, as lower severity signatures might be more prone to false positives.
- ✓
Apply the IPS sensor only to the firewall policy that allows traffic to the web server.
Why this is correct
Applying the IPS sensor to the specific policy that allows traffic to the web server ensures that inspection is targeted. This reduces the scope and potential false positives on other traffic. It also focuses protection where it is needed, which is a best practice for minimizing false positives.
- ✗
Enable all signatures and set the action to 'block' for all.
Why it's wrong here
Enabling all signatures with block action would likely cause many false positives, disrupting legitimate traffic. Many signatures are informational or low severity and may match benign traffic. This approach does not minimize false positives and is not recommended for a production web server.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.