Courseiva
Security Profiles →easyMultiple Choice

NSE4 Security Profiles Practice Question

An administrator wants to apply a safe search policy to enforce strict search results on Google, Bing, and Yahoo. Which security profile feature should be used?

⚠ Common exam trap

It's easy for candidates to confuse 'blocking search engines' (application control or DNS filter) with 'enforcing safe search within search engines' (web filter safe search enforcement), leading them to select an option that prevents access rather than controlling content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Web filter safe search enforcement

Web filter safe search enforcement is the correct feature because it directly integrates with search engines (Google, Bing, Yahoo) to force the use of their built-in safe search parameters (e.g., Google's 'safe=active' parameter appended to URLs). This ensures that explicit content is filtered at the source, regardless of the user's browser settings or search engine choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Web filter safe search enforcement

    Why this is correct

    Safe search enforcement is a built-in Web Filter profile setting that forces supported search engines (Google, Bing, YouTube) to apply strict content filtering by automatically modifying search request URLs (e.g., appending 'safe=active' for Google and 'adlt=strict' for Bing) or by redirecting to a forced-search endpoint. Unlike blocking features, it does not deny access to the search engine; it preserves search capability while scrubbing explicit results, which directly satisfies the administrator's goal. It typically requires HTTPS inspection to rewrite embedded search URLs inside encrypted traffic.

  • ✗

    Application control to block search engines

    Why it's wrong here

    Application control operates on application identification and performs actions like block, allow, or restrict bandwidth, but it cannot alter a search engine's result ranking or content filter. If you configure a FortiOS application control policy to block search-engine applications, users lose the ability to search at all, which is the opposite of enforcing safe search. The correct control is a web-filtering function, not an application-control action, because safe search is about modifying search behavior, not denying the application.

  • ✗

    DNS filter to block search engine domains

    Why it's wrong here

    DNS filtering works at the query-resolution layer, matching requested hostnames against a FortiGuard domain category and then answering with an IP like FortiGuard's block page or dropping the query. Blocking search-engine domains such as google.com or bing.com prevents the client from even initiating a search request, thereby eliminating access entirely. DNS filter can block categories like 'Search Engines and Portals', but that would be a blunt denial of service, not a safe-search mode; it cannot inject search-restriction parameters.

  • ✗

    Web filter URL filter with keyword blocking

    Why it's wrong here

    A URL filter with keyword blocking checks the URL string for configured keywords and then blocks matching pages, but search-engine result pages (SERPs) rarely contain the explicit keywords in the URL itself, so most offensive content passes through. Even if a keyword is present, the filter blocks that specific page rather than telling the search engine to filter all results. Safe search enforcement is an active request-rewriting mechanism, whereas keyword blocking is a passive deny-list that cannot change the provider's content selection logic.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.