NSE4 Security Profiles Practice Question
An administrator wants to block access to websites that host malware. Which FortiGate feature should be configured to achieve this goal?
⚠ Common exam trap
It's easy for candidates to confuse DNS Filtering (which blocks domains at the DNS level) with Web Filtering (which blocks URLs at the HTTP/HTTPS level), but DNS Filtering cannot block specific URL paths or subdirectories, making it insufficient for blocking malware-hosting websites that may share a domain with legitimate content.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Web Filtering profile with FortiGuard categories
FortiGate's Web Filtering profile with FortiGuard categories is the correct feature because it allows administrators to block access to websites based on URL categories, including those known to host malware. FortiGuard maintains a continuously updated database of malicious URLs, and applying a web filtering profile that blocks the 'Malicious Websites' category directly prevents users from accessing such sites. This is the most straightforward and effective method for blocking malware-hosting websites at the proxy or flow-based inspection level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IPS profile
Why it's wrong here
An Intrusion Prevention System (IPS) profile is engineered to inspect traffic for known exploit signatures, anomaly patterns, and protocol deviations, then block or alert on malicious payloads. It does not maintain a URL categorization database, nor does it evaluate the content or category of websites, so it cannot block access based on FortiGuard website categories.
- ✗
DNS Filter profile
Why it's wrong here
A DNS Filter profile operates at the DNS query level, matching requested hostnames against domain-block lists or FortiGuard's DNS-based domain categories. Because it never sees the full URL path, it cannot block a specific page within an otherwise allowed domain, and its category coverage is less granular than URL-level web filtering, making it unsuitable for blocking 'Malicious Web Sites' based on full URL categories.
- ✗
Application Control profile
Why it's wrong here
An Application Control profile identifies and regulates network traffic by recognizing application signatures, such as HTTP, HTTPS, or specific protocols, and enforces policies based on application type rather than web content. It does not classify websites into content categories (e.g., malicious sites), so it is incapable of blocking access to a specific category of websites.
- ✓
Web Filtering profile with FortiGuard categories
Why this is correct
A Web Filtering profile with FortiGuard categories is purpose-built for this task: it leverages FortiGuard's extensive web rating database to classify URLs into categories such as 'Malicious Web Sites' and applies a configurable action (block, warn, or allow) for each category. This profile evaluates the full URL at proxy level, enabling precise blocking of pages that host malware or phishing content.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.