Courseiva

NSE4 System and Network Administration Practice Question

An administrator needs to ensure that all traffic from the internal network to the internet goes through a web proxy for content filtering. Which configuration is required on the FortiGate?

⚠ Common exam trap

Test-takers frequently confuse enabling the web proxy feature in a firewall policy (transparent proxy) with the explicit proxy configuration that requires a separate proxy policy, leading them to select option B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure an explicit web proxy and create a proxy policy.

To enforce web proxy-based content filtering for all internal-to-internet traffic, the FortiGate must be configured with an explicit web proxy (which listens on a specific IP and port, typically 8080) and a corresponding proxy policy that defines the traffic matching criteria and action. This setup ensures that client browsers are configured to send requests to the proxy, and the proxy policy applies content filtering rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable the proxy feature and set the web proxy port to 80.

    Why it's wrong here

    Enabling the proxy feature and setting the web proxy port to 80 only starts an HTTP proxy listener. It does not create any proxy policies or redirect client traffic to that port, so no web filtering or access control is applied. The proxy port alone is a configuration placeholder; traffic will not be proxied unless an explicit proxy setup and matching proxy policies exist.

  • ✗

    Enable web proxy in the firewall policy and set action to accept.

    Why it's wrong here

    Enabling 'web proxy' in a firewall policy and setting action to accept configures a transparent proxy-like behavior, not an explicit proxy. For explicit proxy, traffic is directed to the FortiGate's proxy port by client browsers, and decisions are made by proxy policies, not firewall policies. A firewall policy with web proxy enabled and action set to accept merely allows the connection; it does not create the required proxy policy for explicit proxying.

  • ✓

    Configure an explicit web proxy and create a proxy policy.

    Why this is correct

    An explicit web proxy requires two things: the proxy feature must be enabled and configured on a listening port, and proxy policies must be created to define which users and destinations are allowed, denied, or filtered. This is the correct way to handle 'all traffic' from clients that are configured to use the FortiGate as their proxy. Without a proxy policy, the proxy will accept connections but only return a default or error behavior.

  • ✗

    Configure a transparent proxy by using an SSL inspection profile.

    Why it's wrong here

    A transparent proxy intercepts traffic using firewall policy redirection (e.g., redirect-to-proxy) and typically requires an SSL inspection profile to decrypt HTTPS traffic. It is not the same as an explicit proxy—clients do not configure their browsers, and the traffic handling is governed by firewall policies, not proxy policies. The correct answer explicitly requires an 'explicit web proxy,' so a transparent proxy using SSL inspection is the wrong approach.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.