NSE4 Security Profiles Practice Question
An administrator runs the CLI command: 'diagnose sys session list | grep -i dns' and sees sessions with dst port 53. The administrator has configured a DNS filter profile on the firewall policy. However, DNS requests are not being filtered. What is the MOST likely cause?
⚠ Common exam trap
Test-takers frequently assume DNS filtering works like other security profiles (e.g., web filtering) that can operate in flow-based mode, but DNS filtering specifically requires proxy-based inspection due to the nature of DNS protocol inspection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS filtering requires proxy-based inspection mode on the policy
DNS filtering on FortiGate requires proxy-based inspection mode because it needs to reassemble and inspect the full DNS transaction (request and response) to apply filtering rules. Flow-based inspection only examines individual packets and cannot perform the deep application-layer analysis needed for DNS filtering. Therefore, even if the DNS filter profile is correctly applied to the policy, it will not work unless the policy's inspection mode is set to proxy-based.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The DNS filter profile is applied to the wrong policy direction
Why it's wrong here
Applying the DNS filter profile to a policy that handles traffic in the wrong direction (e.g., inbound rather than outbound) would prevent the profile from being evaluated for the DNS queries you intend to filter. However, even with the correct direction, the filter still would not be applied because DNS filtering is a proxy-only inspection feature — the CLI command 'diagnose sys session' would show sessions but not enforce filtering. Thus, the wrong direction is not the root cause described; it is a separate configuration issue.
- ✓
DNS filtering requires proxy-based inspection mode on the policy
Why this is correct
FortiGate has two inspection modes: flow-based and proxy-based. DNS filtering uses the proxy engine to inspect the DNS query and compare the domain against a FortiGuard category, so the policy controlling the client DNS traffic must be configured for proxy-based inspection mode. If the policy is left in flow mode, the FortiGate performs session-based forwarding and does not decrypt/intercept the DNS protocol payload, so the DNS filter profile is silently ignored. This is the correct reason the DNS filter is ineffective for the administrator's setup.
- ✗
The DNS filter profile has no rules defined
Why it's wrong here
A DNS filter profile with no rules defined would not block or log any domains, but the profile itself would still function if applied to a proxy-based policy — it would simply allow all DNS traffic by default. The fact that the administrator's DNS filtering is not working at all cannot be explained by an empty rule set because proxy mode is the prerequisite; without proxy-mode inspection, even a fully populated DNS filter profile is never examined. Therefore, 'no rules' is not the cause and would not make the FortiGate ignore the profile.
- ✗
The FortiGate is in transparent mode
Why it's wrong here
The FortiGate's operating mode (transparent vs. NAT/route) does not change the availability of proxy-based inspection or DNS filtering. In transparent mode, the FortiGate still inspects traffic through security policies, and you can set inspection mode to proxy on those policies. DNS filtering works in transparent mode exactly as it does in NAT mode; the only requirement is that the relevant policy uses a proxy-based inspection profile. So being in transparent mode is not a reason why the DNS filter would fail.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.