Courseiva
Security Profiles →mediumMultiple Choice

NSE4 Security Profiles Practice Question

An administrator wants to allow users to override a blocked category (e.g., Social Networking) by entering an administrator-defined password. Which of the following must be configured?

⚠ Common exam trap

It's easy for candidates to confuse the Web Filter override with creating a separate firewall policy or changing the filter mode, not realizing that the override is a specific feature requiring both the override toggle and an authentication scheme to be configured within the web filter profile itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable 'Override' in the Web Filter profile and configure an authentication scheme

To allow users to override a blocked web category by entering an administrator-defined password, you must enable the 'Override' feature within the Web Filter profile and configure an authentication scheme (e.g., using a local user or LDAP group). This allows users to bypass the block temporarily after authenticating with the defined password, rather than permanently changing the policy or filter mode.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a DNS filter to bypass the block

    Why it's wrong here

    Configuring a DNS filter to bypass the block does not invoke the Web Filter override mechanism. A DNS filter can only change how domains resolve and can set sites to 'Allowed' or 'Monitored', but it lacks any concept of user authentication or per-user exception lists. Therefore, it cannot provide the authenticated, time-limited override that FortiGate's Web Filter override feature delivers. The two features operate at different layers, so adjusting DNS filtering would not affect the Web Filter profile's block action on subsequent sessions.

  • ✗

    Create a separate firewall policy with a higher priority that permits the traffic

    Why it's wrong here

    A separate firewall policy with a higher priority would permit the traffic at the session level, but any Web Filter profile attached to that policy would still block the URL based on its category. Firewall policy order only determines which security profiles are applied, not whether the profiles' actions are skipped. To allow a user override, you must explicitly enable the override feature in the Web Filter profile with a valid authentication scheme, not simply reorder firewall rules.

  • ✗

    Set the web filter profile to 'Monitor' mode instead of 'Block'

    Why it's wrong here

    Switching the Web Filter profile to 'Monitor' mode would prevent the page from being blocked, so there is no blocked page for the user to override. In Monitor mode, the FortiGate logs category matches but permits all requests, which removes the need for an override rather than implementing one. The override feature is designed for 'Block' or 'Warning' actions; without any block action, users never see the override prompt or trigger the authentication step.

  • ✓

    Enable 'Override' in the Web Filter profile and configure an authentication scheme

    Why this is correct

    To correctly enable user overrides, you must turn on 'Override' in the Web Filter profile and configure an authentication scheme (e.g., local password or LDAP username/password) so the FortiGate can validate the user who submits the override request. You also need to define an authentication rule that lists which users or groups are allowed to override, and you can optionally set a duration for each override session. Once these are in place, users encountering a blocked page are prompted to enter credentials, and a successful authentication creates a temporary, logged exception that is visible in the override history.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.