NSE4 System and Network Administration Practice Question
An administrator needs to configure DNS on a FortiGate so that internal hosts can resolve external domain names. Which two settings are required? (Choose two.)
⚠ Common exam trap
Many exam-takers think a firewall policy is required for DNS traffic, but the FortiGate's DNS proxy handles the forwarding internally, making the explicit policy unnecessary unless the proxy is disabled and hosts send queries directly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure DNS servers under System > DNS.
Configuring DNS servers under System > DNS is the fundamental step that tells the FortiGate which external DNS resolvers (e.g., 8.8.8.8) to use for resolving domain names. Without this, the FortiGate cannot forward DNS queries from internal hosts to the internet. Option C is correct because enabling the DNS proxy on the FortiGate allows it to intercept DNS requests from internal clients, cache responses for performance, and forward them to the configured DNS servers, which is essential for internal hosts to resolve external domains through the FortiGate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure DNS servers under System > DNS.
Why this is correct
DNS server addresses must be specified for the FortiGate to perform resolution.
- ✗
Create a firewall policy allowing DNS traffic from internal to external.
Why it's wrong here
DNS proxy traffic is handled internally; no separate policy needed if proxy is enabled.
- ✓
Enable DNS proxy on the FortiGate.
Why this is correct
The DNS proxy allows the FortiGate to forward DNS requests from internal hosts to external servers.
- ✗
Set the FortiGate's hostname to the domain name.
Why it's wrong here
Hostname is irrelevant for DNS resolution.
- ✗
Configure a static route for DNS servers.
Why it's wrong here
If the DNS servers are reachable via the default route, no special route is needed.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 282 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.