Courseiva
System and Network AdministrationeasyMultiple SelectObjective-mapped

NSE4 System and Network Administration Practice Question

An administrator needs to configure DNS on a FortiGate so that internal hosts can resolve external domain names. Which two settings are required? (Choose two.)

⚠ Common exam trap

Many exam-takers think a firewall policy is required for DNS traffic, but the FortiGate's DNS proxy handles the forwarding internally, making the explicit policy unnecessary unless the proxy is disabled and hosts send queries directly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure DNS servers under System > DNS.

Configuring DNS servers under System > DNS is the fundamental step that tells the FortiGate which external DNS resolvers (e.g., 8.8.8.8) to use for resolving domain names. Without this, the FortiGate cannot forward DNS queries from internal hosts to the internet. Option C is correct because enabling the DNS proxy on the FortiGate allows it to intercept DNS requests from internal clients, cache responses for performance, and forward them to the configured DNS servers, which is essential for internal hosts to resolve external domains through the FortiGate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure DNS servers under System > DNS.

    Why this is correct

    DNS server addresses must be specified for the FortiGate to perform resolution.

  • Create a firewall policy allowing DNS traffic from internal to external.

    Why it's wrong here

    DNS proxy traffic is handled internally; no separate policy needed if proxy is enabled.

  • Enable DNS proxy on the FortiGate.

    Why this is correct

    The DNS proxy allows the FortiGate to forward DNS requests from internal hosts to external servers.

  • Set the FortiGate's hostname to the domain name.

    Why it's wrong here

    Hostname is irrelevant for DNS resolution.

  • Configure a static route for DNS servers.

    Why it's wrong here

    If the DNS servers are reachable via the default route, no special route is needed.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 282 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.