NSE4 Security Profiles Practice Question
An administrator is configuring web filtering on a FortiGate. Which TWO statements about web filtering profiles are correct?
⚠ Common exam trap
Watch out — candidates often confuse the scope of web filtering profiles, assuming they require authentication (B) or are global by default (D), or they mistakenly think SSL inspection is configured within the web filtering profile (E) instead of as a separate inspection profile.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Web filtering profiles can be used together with application control profiles.
Web filtering profiles and application control profiles operate independently at different layers of the FortiGate security fabric. Web filtering inspects HTTP/HTTPS traffic against URL categories and ratings, while application control identifies and controls application-level traffic (e.g., Facebook, Skype) using deep packet inspection. They can be applied together in a single security policy to provide layered protection without conflict.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Web filtering profiles can be used together with application control profiles.
Why this is correct
On FortiGate, web filtering and application control profiles are complementary UTM features that can both be inserted into the same firewall policy. A web filtering profile evaluates HTTP/HTTPS requests against URL categories and FortiGuard ratings, while an application control profile identifies and controls the applications traversing the network, regardless of the URL used. This allows you to block, for example, a URL category while simultaneously allowing or restricting the specific applications that the traffic uses.
- ✗
Web filtering profiles can only be applied to users who are authenticated.
Why it's wrong here
Web filtering profiles are not reliant on user authentication; they apply to all traffic that matches the firewall policy in which the profile is referenced. Even unauthenticated users or IP ranges receive the configured URL blocking and allow/monitor actions. Authentication can be used to track per-user logs or apply identity-based policies, but it is an optional feature, not a prerequisite for web filtering enforcement.
- ✓
Web filtering profiles can block access to websites based on URL categories and ratings.
Why this is correct
FortiGate web filtering profiles perform URL lookups against the FortiGuard database, which classifies millions of websites into categories such as social media, malware, or gambling, and assigns a risk rating. The administrator sets an action for each category—allow, monitor, or block—and the firewall enforces the corresponding rule when a user requests a URL. Static or dynamic rating overrides can also tailor the profile for a specific organization.
- ✗
Web filtering profiles are applied globally by default.
Why it's wrong here
Web filtering profiles are not applied globally by default; a FortiGate enforces them only when the profile is explicitly selected in an individual firewall policy. If no web filtering profile is referenced in a policy, that traffic passes without URL filtering, regardless of how many profiles you have created. This per-policy design allows different security postures for different interface zones, source addresses, or user groups.
- ✗
Web filtering profiles are used to configure SSL certificate inspection.
Why it's wrong here
SSL certificate inspection is handled separately through SSL/SSH inspection profiles, not web filtering profiles. While web filtering inspects the HTTP/HTTPS URLs and categories, the SSL inspection profile determines whether the FortiGate decrypts traffic after presenting its CA to the client. Without an appropriate SSL inspection profile, the web filter may only see the SNI or IP address of HTTPS traffic, reducing classification accuracy, but that does not mean web filtering profiles themselves perform certificate inspection.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.