NSE4 · domain
Security Profiles
This domain covers FortiGate security profiles: antivirus, web filter, application control, IPS, email filter, DLP, and SSL inspection. Questions test configuration, CLI diagnostics like 'diagnose debug rating', and troubleshooting false positives or certificate trust issues. You must know how profiles interact with firewall policies and how to tune them for accurate detection.
Focused practice
Practice Security Profiles questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Security Profiles
Watch out for
Common Security Profiles exam traps
- ▸Forgetting that deep SSL inspection requires the FortiGate CA certificate to be trusted on client devices, or sites will fail to load.
- ▸Assuming 'diagnose debug rating' timeouts are always a FortiGate issue, when the most likely cause is no route or DNS to FortiGuard servers.
- ▸Believing email filter spam blocking is perfect; false positives require tuning with allow lists or adjusting spam action thresholds.
Question index
All Security Profiles questions (182)
Click any question to see the full explanation, or start a practice session above.
An administrator configures a DLP profile to detect credit card numbers in email traffic. The DLP rule uses a regular expression. However, the DLP sensor is not triggering on emails containing credit card numbers. What is a likely reason?
Hard2A FortiGate administrator is configuring IPS to protect against a known exploit targeting a web server. The administrator wants to ensure that the IPS engine can decode the HTTP protocol. Which TWO actions are necessary?
Medium3A FortiGate configured with IPS anomaly detection is generating false positives for the 'tcp_syn_flood' anomaly. The administrator wants to reduce the false positives without completely disabling the detection. Which action should the administrator take?
Hard4Which inspection mode allows FortiGate to perform virus scanning by reassembling the entire file in memory before scanning, providing better detection but potentially higher latency?
Easy5You run the following CLI command on a FortiGate: diagnose sys session filter dport 443 diagnose sys session list The output shows many sessions with 'proto=6 proto_state=01 duration=3600 expire=3599'. What does this indicate about the traffic?
Hard6An administrator wants to block all traffic from the 'P2P' application category but allow traffic from 'File Sharing' applications like Dropbox. Which THREE configurations are required to achieve this?
Hard7A school district uses a FortiGate to filter web traffic for students. The administrator wants to enforce that Google searches are filtered for explicit content. Which configuration should be applied?
Medium8An administrator wants to block access to websites that host malware. Which FortiGate feature should be configured to achieve this goal?
Easy9An administrator wants to prevent data leakage by blocking outbound emails that contain credit card numbers. Which security profile should be configured?
Medium10A FortiGate is configured with an SSL deep inspection profile that uses 'Certificate Inspection' (not 'Full SSL Inspection'). Which of the following is TRUE about this configuration?
Hard11A FortiGate administrator configures an email filter profile to block spam. Users report that some legitimate emails are being blocked. The administrator wants to reduce false positives while still blocking spam. What should the administrator do?
Medium12A FortiGate is configured with flow-based inspection and an IPS profile. The administrator runs 'diagnose ips session list' and sees many sessions with 'state=bypass'. What does this indicate?
Hard13Which two inspection modes are available for antivirus scanning on a FortiGate?
Easy14Which TWO statements about IPS in FortiGate are true?
Hard15Match each Fortinet HA mode to its description.
Medium16Which TWO are valid types of SSL/TLS inspection available on FortiGate?
Easy17A mid-sized company has a FortiGate 100F running FortiOS 7.2. They have two internal networks: Trusted (10.1.1.0/24) for employees and Guest (10.2.2.0/24) for visitors. The Guest network has a firewall policy that allows internet access only, with an application control profile that blocks all peer-to-peer and gaming applications. Recently, users on the Guest network have been able to play online games (e.g., Fortnite) despite the block. The administrator checks the application control profile and confirms that 'Fortnite' is listed as blocked. There are no other policies allowing Guest traffic. The administrator also notices that the Guest policy has 'set utm-status enable' and the application control profile is applied. What is the most likely reason that Fortnite is not being blocked?
Medium18A FortiGate administrator wants to block spam emails destined for internal users. The FortiGate receives SMTP traffic on port 25. What is the most effective way to filter spam using the email filter profile?
Medium19Match each FortiGate firewall policy action to its result.
Medium20A FortiGate administrator is troubleshooting an issue where a user receives a certificate error when accessing a web server. The administrator has configured SSL deep inspection with a custom CA certificate. The error indicates the certificate is not trusted. Which THREE actions could resolve this issue? (Choose three.)
Hard21An administrator is configuring email filtering on FortiGate to block spam. Which of the following is required for FortiGate to filter inbound email directly?
Medium22A FortiGate administrator runs the command 'diagnose application urlfilter 0 status' and sees 'status: enable' but users report that some malicious URLs are not blocked. The web filter profile uses FortiGuard categories with 'block' action. What should the administrator check next?
Hard23Which security profile type requires a FortiSandbox license to enable advanced detection features?
Easy24A FortiGate is configured with SSL inspection and web filtering. The administrator notices that some HTTPS traffic is being blocked even though the URL is in an allowed category. What could be the cause?
Hard25What is the purpose of enabling 'Safe Search' in a web filter profile on a FortiGate?
Easy26Which security profile is used to detect and prevent spam email messages?
Easy27A FortiGate administrator needs to prevent employees from using peer-to-peer file sharing applications such as BitTorrent. The administrator creates an application control profile with a rule to block the 'Peer-to-Peer' application category. After applying the profile to the firewall policy, users can still use BitTorrent. What is the most likely cause?
Medium28An administrator is configuring web filtering on a FortiGate. Which TWO statements about web filtering profiles are correct?
Medium29Refer to the exhibit. An administrator has configured the SSL/SSH profile shown. However, users are unable to access HTTPS websites. What is the most likely cause?
Easy30A network administrator is troubleshooting why certain web-based applications are not being identified by application control. The applications are accessed over HTTPS. What is the most likely missing configuration?
Medium31A security administrator wants to ensure that all DNS queries from internal users are filtered to block access to known malicious domains. Which TWO configurations must be applied?
Medium32A FortiGate is configured with an IPS profile to protect a web server. The administrator notices that some attacks are not being detected. The IPS signature database is up to date. What should the administrator check first?
Medium33A FortiGate administrator has configured a firewall policy with SSL deep inspection using a forward trust CA certificate. When users access an HTTPS website with a valid certificate, they still receive a certificate warning. What is the MOST likely reason?
Medium34An administrator configures a DLP profile to detect Social Security numbers in outbound traffic. The profile is applied to an outbound HTTP policy. Which TWO additional configurations are necessary for the DLP to inspect HTTPS traffic?
Medium35An admin runs the following command on a FortiGate: 'diagnose sys session filter dport 443' and sees output: 'proto=6 proto_state=01 duration=3600 expire=3599'. What does this indicate?
Hard36An administrator needs to block users from uploading files containing credit card numbers to external websites. Which TWO actions must be configured? (Choose two.)
Medium37Which TWO actions can cause SSL inspection to fail with certificate errors on client browsers? (Choose two.)
Medium38After enabling SSL inspection, a user receives a warning 'The certificate is not trusted' in the browser. The administrator has installed the CA certificate on the client. What else could be the cause?
Medium39An administrator configured SSL inspection with 'deep-inspection' profile. Users report that some websites fail to load with certificate errors. The firewall policy is correct. What is the most likely reason?
Hard40A company uses deep SSL inspection to filter traffic. Users report that some HTTPS sites are not loading. The administrator checks the FortiGate and sees that the certificate for the sites is not trusted on the client machines. What is the most likely cause?
Medium41An administrator configures an antivirus profile in proxy-based inspection mode on a FortiGate. However, SMTP traffic is not being scanned for viruses. The firewall policy includes the antivirus profile and the FortiGate has a valid FortiGuard subscription. What is the most likely cause?
Medium42A company wants to block all peer-to-peer file sharing applications on the network. Which FortiGate feature should be used to achieve this goal?
Easy43A FortiGate is configured to integrate with FortiSandbox for advanced threat detection. The antivirus profile is set to send files to FortiSandbox when a virus is detected. What action does FortiGate take on the file while it is being analyzed by FortiSandbox?
Medium44An administrator receives reports that some internal users can access Facebook despite a web filtering profile that blocks the 'Social Networking' category. The policy is configured with deep inspection. Which THREE checks should the administrator perform to troubleshoot this issue?
Hard45A FortiGate with antivirus in flow-based inspection mode is not detecting a known virus in HTTP traffic. The same virus is detected when using proxy-based inspection. What is the most likely reason?
Medium46A security administrator is configuring an IPS sensor on a FortiGate to protect a web server. The sensor includes a signature that detects a specific HTTP exploit. The administrator wants to ensure that the signature blocks the attack but also generates a log entry for each detection. Which action should be taken for that signature in the IPS sensor?
Hard47A company wants to block all HTTP traffic but allow HTTPS. Which SSL inspection method should be used on the firewall policy?
Easy48A FortiGate administrator runs the following command and sees: 'diagnose ips anomaly list' returns no entries, but the IPS sensor is configured with anomaly signatures. What is the MOST likely reason the signatures are not appearing?
Hard49A FortiGate administrator notices that some users can bypass the web filter to access prohibited categories. The web filter profile is applied to the firewall policy. Which TWO actions should the admin take to determine why the filter is being bypassed? (Choose two.)
Hard50A company is deploying FortiGate for outbound web filtering. They want to block users from accessing social media sites during business hours, but still allow access to cloud-based productivity tools like Office 365. Which approach should the administrator use to meet this requirement?
Medium51An administrator is configuring an IPS sensor to protect a web server. The administrator wants to ensure that the IPS blocks attacks targeting the web server, but also wants to minimize false positives. Which two actions should the administrator take when configuring the IPS sensor? (Choose two.)
Hard52Which web filtering feature allows an administrator to force web search engines to filter explicit content in search results, regardless of the user's browser settings?
Easy53Which SSL/TLS inspection mode only validates the server certificate without decrypting the traffic?
Easy54Which security profile type is used to prevent sensitive data such as credit card numbers from being sent out of the network via email or web traffic?
Easy55A FortiGate administrator is troubleshooting why antivirus scanning is not working for HTTPS traffic. Which TWO steps should be verified?
Medium56Match each FortiGate NAT type to its description.
Medium57A FortiGate administrator wants to block all traffic to websites that are categorized as 'Malware' and 'Phishing'. Which security profile should be configured to achieve this goal?
Easy58What is the purpose of the DNS filter security profile on a FortiGate?
Easy59Which FortiGate security profile is BEST suited for blocking DNS queries to known malicious domains?
Easy60An administrator needs to ensure that all HTTPS traffic to a critical server is inspected by the IPS. The server uses a valid certificate from a public CA. Which THREE steps are required to achieve this?
Hard61A network administrator notices that some users can access blocked web categories despite a web filter profile applied to the policy. The admin runs 'diagnose debug rating' and sees 'rating not allow' for the category. What is the MOST likely cause?
Medium62A company policy requires that all web searches by employees use safe search. Which setting should be configured in the web filtering profile?
Medium63An administrator wants to block all peer-to-peer (P2P) file sharing applications such as BitTorrent and eMule on the network. Which THREE steps should the administrator take?
Medium64Drag and drop the steps to capture traffic on a FortiGate interface using the CLI into the correct order.
Medium65A network administrator notices that HTTP traffic is being scanned by the antivirus profile, but HTTPS traffic to the same web server is not being scanned. The firewall policy has the antivirus profile applied and SSL inspection is set to 'certificate-inspection'. What is the most likely reason HTTPS traffic is not being scanned?
Medium66Which inspection mode in the antivirus profile processes traffic by buffering the entire file before scanning, allowing more thorough detection but potentially increasing latency?
Easy67A FortiGate administrator wants to block access to Facebook for all internal users. However, the administrator must ensure that the CEO's computer (IP 10.0.0.100) is exempted. Which TWO steps should the administrator take? (Choose two.)
Medium68An administrator has configured DLP sensors to detect credit card numbers in outgoing traffic. However, the administrator notices that traffic containing credit card numbers is still passing through undetected. The firewall policy uses flow-based inspection. What is the MOST likely reason DLP is not detecting the data?
Hard69A company with 500 users has a FortiGate 1000D running FortiOS 7.2. They have configured full SSL inspection and web filtering to block malware and phishing sites. The administrator receives complaints that some users cannot access a legitimate business website (https://vendor.example.com). The administrator checks the FortiGate logs and sees that the connection is allowed by the firewall policy and web filter. However, the user's browser shows 'ERR_CERT_AUTHORITY_INVALID'. The administrator verifies that the FortiGate's CA certificate is installed on all client machines. Further investigation reveals that the vendor's website uses a certificate signed by a private CA that is not trusted by the FortiGate. The administrator wants to resolve the issue without disabling SSL inspection for the whole website or compromising security. What should the administrator do?
Medium70An administrator enables deep inspection for HTTPS traffic. Users report that they cannot access some websites because of certificate errors. The administrator wants to override these errors and allow access. What should be configured?
Hard71What is the purpose of enabling 'DNS filter' in a security profile?
Easy72What is the purpose of the 'DNS Filter' feature on a FortiGate?
Easy73What is the PRIMARY purpose of enabling 'Safe Search' in a web filter profile?
Easy74Which IPS detection method uses a baseline of normal traffic and alerts when deviations exceed a threshold?
Easy75Which of the following best describes the function of FortiGuard web filtering categories?
Easy76An administrator receives alerts about a possible data breach. Sensitive data (credit card numbers) might be leaving the network via email. The admin wants to detect and block such emails. Which THREE security profiles should be combined?
Hard77An administrator wants to block users from uploading sensitive documents through webmail. Which security profile should be configured on the FortiGate to achieve this goal?
Medium78Refer to the exhibit. An administrator has created an IPS sensor with two entries. The first entry sets severity 'medium' and action 'block'. The second entry sets severity 'critical' and action 'block'. What will happen when a packet triggers an IPS signature with severity 'low'?
Easy79A FortiGate is configured with an IPS profile that includes a signature with a 'Pass' action. The firewall policy uses this IPS profile. What will happen when traffic matching that signature is detected?
Hard80An administrator wants to integrate FortiSandbox with a FortiGate to analyze suspicious files. Which security profile must be configured to send files to FortiSandbox?
Medium81A company with 500 employees uses FortiGate as their internet gateway. They recently enabled SSL deep inspection using the built-in CA certificate. After deployment, many users report that they cannot access their online banking websites. The error message in the browser says 'The certificate is not trusted'. The administrator has already pushed the FortiGate CA certificate to all domain-joined computers via Group Policy. However, the problem persists for banking sites. The administrator also notices that banking sites load fine on mobile devices that do not have the CA certificate installed. What is the most likely cause and solution?
Hard82Drag and drop the steps to perform a factory reset on FortiGate via CLI into the correct order.
Medium83Given the above IPS sensor configuration, what will happen when traffic matching a high-severity IPS signature is detected?
Hard84An administrator has configured an IPS sensor to block critical-severity attacks. However, after a week, they notice that a known exploit (CVE-2021-44228) is still getting through. Which configuration change should be made to improve detection?
Hard85Which FortiGate security feature can be used to block outgoing emails that contain specific keywords, such as confidential information?
Easy86An administrator runs the CLI command: 'diagnose sys session list | grep -i dns' and sees sessions with dst port 53. The administrator has configured a DNS filter profile on the firewall policy. However, DNS requests are not being filtered. What is the MOST likely cause?
Hard87An administrator runs the command 'diagnose ips anomaly list' and sees many entries for 'tcp_src_session' with high counts. Users report slow internet. What is the most likely issue?
Hard88A company recently deployed FortiGate with application control to manage cloud application usage. They want to allow Google Drive for business but block personal Google accounts. Which application control configuration approach is most effective?
Medium89Which TWO of the following are required for full SSL inspection to work correctly?
Medium90An administrator is troubleshooting why an application control profile is not detecting a custom application that uses a non-standard port. The administrator wants to ensure the application is properly identified. Which THREE steps should the administrator take? (Choose three.)
Hard91An organization uses FortiSandbox to detect advanced threats. The administrator wants to ensure that files downloaded from the internet are sent to FortiSandbox for analysis before being delivered to users. Which Antivirus profile setting should be configured?
Medium92Which THREE steps are necessary when configuring SSL deep inspection on FortiGate? (Choose three.)
Hard93A FortiGate is configured with an application control profile to allow only 'business-approved' applications. Users are still able to use Skype for Business. The admin wants to ensure that only Skype for Business is allowed and other Skype variants are blocked. Which THREE steps should the admin take? (Choose three.)
Medium94An administrator wants to allow users to override a blocked category (e.g., Social Networking) by entering an administrator-defined password. Which of the following must be configured?
Medium95An administrator configures an email filter profile to block spam. Despite correct configuration, spam emails still reach users' inboxes. The FortiGate is deployed as a transparent bridge. What is the most likely reason?
Medium96A FortiGate is configured with a firewall policy that applies an Application Control profile and a Web Filter profile. The administrator wants to log all traffic blocked by the Web Filter profile. Which TWO configurations are required?
Medium97An administrator needs to ensure that users cannot upload files to a specific cloud storage service via HTTPS, while still allowing them to view and download files from the same service. The FortiGate is currently performing SSL deep inspection on all outbound HTTPS traffic. Which security profile should the administrator configure to meet this requirement?
Medium98An administrator wants to block an application named 'Skype' on the network. They create an application control profile and add a rule to block 'Skype'. However, after applying the profile to the policy, users can still use Skype. What is the most likely reason?
Medium99Which security profile component is specifically designed to prevent data exfiltration by inspecting outgoing traffic for sensitive data patterns?
Easy100An organization uses FortiSandbox to analyze suspicious files. The FortiGate is configured to send files to FortiSandbox for analysis when the antivirus scan fails to reach a verdict. Which antivirus inspection mode must be used on the firewall policy for this integration to work?
Medium101A FortiGate administrator wants to block spam emails sent to the company's mail server. The mail server is behind the FortiGate. Which THREE configurations should be applied?
Medium102A network administrator notices that a FortiGate IPS sensor is not detecting any attacks, even though there is known malicious traffic on the network. Which initial troubleshooting step should the administrator take?
Easy103A FortiGate administrator configures SSL deep inspection on a policy using a self-signed CA certificate. Users report that they see a certificate warning in their browsers when accessing HTTPS sites. What is the most effective solution to eliminate these warnings?
Hard104A company is implementing SSL/TLS inspection on a FortiGate to monitor encrypted traffic. They want to ensure that traffic to high-risk categories is blocked, while traffic to financial sites is inspected but not blocked. The administrator creates an SSL inspection profile that deep-inspects all traffic except traffic to financial sites. However, users report that they cannot access financial websites. What is the most likely cause?
Hard105Which FortiGate feature allows you to block access to specific URL categories such as 'Social Media' or 'Gambling'?
Easy106A user reports that a legitimate website is being blocked by FortiGate web filtering. The administrator checks and finds that the URL category is 'Unrated'. What is the most likely cause?
Hard107Which THREE factors should be considered when tuning IPS to reduce false positives?
Hard108An administrator has configured an SSL deep inspection profile with 'certificate inspection' for a firewall policy. Users report that they receive certificate errors when accessing HTTPS sites. What is the MOST likely reason?
Medium109A network administrator wants to prevent users from downloading files with .exe extensions via HTTP and HTTPS. Which security profile feature should be used?
Easy110An administrator wants to ensure that search engine results from Google, Bing, and Yahoo are filtered to exclude explicit content when users perform searches. Which feature should the administrator configure in the web filter profile?
Medium111An administrator configures a DLP sensor to detect credit card numbers in traffic. However, the sensor is not detecting any credit card numbers even though they are present in emails. What could be the reason?
Medium112A FortiGate in flow-based mode is configured with an antivirus profile to block infected files. A user downloads a .zip file containing a known virus, but the download is allowed and the file is not quarantined. What is the MOST likely reason?
Hard113Which of the following is a prerequisite for SSL deep inspection to work correctly on FortiGate?
Easy114A network admin wants to block all traffic from the BitTorrent application. The admin has enabled application control on the firewall policy. Which step is necessary to achieve this?
Medium115An organization uses FortiMail for email filtering and FortiGate for web filtering. The administrator wants to ensure that email traffic is filtered for spam and malware before reaching the internal mail server. Which TWO steps should be taken? (Choose two.)
Hard116An administrator wants to apply a safe search policy to enforce strict search results on Google, Bing, and Yahoo. Which security profile feature should be used?
Easy117An administrator wants to configure a DNS filter to block access to known malicious domains and also enforce safe search on search engines. Which THREE settings are required in the DNS filter profile? (Choose three.)
Medium118An administrator runs the following CLI command and sees the output: 'diagnose sys session list | grep -A 5 10.1.1.100' and finds a session with 'proto=6 proto_state=01 duration=3600 expire=3599'. What does this indicate about the session?
Medium119An administrator runs 'diagnose ips anomaly list' and sees the following output: List of anomaly events: ID: 1, Type: tcp_syn_flood, Status: triggered, Count: 1500, Threshold: 1000 What does this indicate?
Hard120Which of the following best describes the difference between flow-based and proxy-based inspection for antivirus scanning?
Medium121A network administrator wants to prevent users from accessing known malicious websites using FortiGate. Which security profile should be applied to the firewall policy to achieve this goal?
Easy122An administrator wants to block upload of files containing credit card numbers via web forms. Which security profile should be used?
Medium123When configuring SSL inspection, which type of inspection decrypts and inspects all HTTPS traffic including applications using non-standard ports?
Easy124A FortiGate administrator wants to block outgoing DNS requests to known malware domains. Which security profile should be used?
Medium125What is the primary function of protocol decoders in the FortiGate IPS engine?
Easy126What is the primary purpose of FortiSandbox integration with FortiGate antivirus?
Easy127Drag and drop the steps to configure a VLAN interface on FortiGate into the correct order.
Medium128A FortiGate is configured with SSL deep inspection using a self-signed CA certificate. Users report that they see a certificate warning in their browser when accessing HTTPS sites. The admin wants to eliminate these warnings. What should the admin do?
Hard129Refer to the exhibit. A FortiGate SSL VPN user is unable to connect. The debug output shows the above error. What is the most likely cause?
Hard130An administrator configures an application control profile to block 'Facebook' and 'Twitter' using application signatures. Users can still access Facebook via HTTPS. The firewall policy has application control enabled and SSL deep inspection is not configured. Why is Facebook not blocked?
Hard131An administrator runs the command shown in the exhibit and sees anomalies detected from 10.1.1.100 to 10.2.2.200. The IPS sensor's anomaly settings are configured with the default actions. What will be the default action for the ICMP Flood anomaly?
Hard132A FortiGate administrator wants to block access to gambling websites using web filtering. Which FortiGuard category should be blocked?
Easy133An administrator integrates FortiGate with FortiSandbox for advanced threat detection. The FortiGate is configured to send files to FortiSandbox for analysis. Despite correct configuration, files are not being submitted. The administrator runs 'diagnose debug application fortisandbox -1' and sees 'no server configured'. What is the issue?
Hard134A FortiGate administrator wants to ensure that all DNS queries to known malware domains are blocked. The firewall policy allows DNS traffic. Which security profile must be applied?
Medium135A network administrator wants to ensure that all users are blocked from accessing websites categorized as 'Pornography' and 'Hacking' on a FortiGate. Which TWO actions should the administrator take? (Choose two.)
Medium136A FortiGate administrator needs to ensure that all outbound DNS queries from internal clients are inspected for malicious domains. The administrator has a DNS filter profile configured. What additional configuration is required on the firewall policy to make the DNS filter effective?
Medium137Which IPS detection method analyzes traffic patterns over time to identify attacks that are characterized by a threshold of events?
Easy138An administrator wants to prevent employees from uploading sensitive credit card numbers via web forms. Which security profile feature is MOST appropriate to achieve this?
Medium139An administrator needs to ensure that IPS signatures are updated automatically on the FortiGate. Which configuration should be verified?
Easy140An administrator is configuring an IPS profile on FortiGate to detect and block SQL injection attacks. The profile must be applied to inbound traffic to a web server. Which TWO settings should the administrator enable to achieve this goal? (Choose two.)
Hard141A network administrator notices that users can access websites categorized as 'Pornography' despite a web filter profile blocking that category. The firewall policy uses the web filter profile and is applied to the users' traffic. What is the MOST likely cause?
Medium142A large enterprise uses a FortiGate 600E in NAT mode to protect its internal network. The security team has implemented an Application Control profile that categorizes applications and allows only 'Business' and 'General-Interest' categories. They have also applied an IPS sensor with default settings and enabled SSL inspection for outbound traffic. Recently, the helpdesk has received reports that some users cannot access a critical cloud-based CRM application, while others can. The CRM uses HTTPS on port 443. The Application Control profile is applied to the firewall policy for outbound traffic. The IPS sensor is also applied. The FortiGate is not configured for load balancing. Which of the following is the most likely cause of the issue?
Hard143Which TWO of the following are best practices when configuring IPS on a FortiGate in a high-throughput environment?
Hard144A network administrator configures an application control profile to block social media applications. Users can still access Facebook through a web browser. What is the MOST likely reason?
Medium145An administrator wants to block the use of social media applications like Facebook and Twitter on the company network. Which security profile should be used?
Easy146A FortiGate administrator is configuring intrusion prevention (IPS) for a web server. The administrator wants to both block known exploits and detect anomalous traffic patterns. Which TWO features should be enabled? (Choose two.)
Medium147Which FortiGate feature allows the administrator to scan SMTP, IMAP, and POP3 traffic for spam and apply actions such as tagging or discarding?
Easy148An administrator configures a web filter profile to block the URL category 'Pornography'. The profile is applied to a policy for the sales department. Users report they can still access some sites that should be blocked. The administrator verifies that the FortiGuard web filter service is licensed and the FortiGate has internet connectivity. What should the administrator check next?
Hard149A FortiGate administrator needs to prevent data leakage by blocking the upload of files containing credit card numbers via web traffic. Which THREE components must be configured? (Choose three.)
Medium150An administrator configures SSL deep inspection with a CA certificate. Users accessing an internal site (internal.company.com) receive a certificate error. The administrator wants to avoid the error without disabling deep inspection. What should be done?
Hard151An administrator has configured the policy shown in the exhibit. Traffic to the web server at 10.0.1.10 over HTTPS is allowed, but users complain that they cannot access the web server's login page. The IPS sensor 'High_Security_Sensor' has a signature that blocks SQL injection attempts. The application list 'Block_Social_Media' blocks Facebook and Twitter. What is the most likely cause of the issue?
Medium152A FortiGate administrator receives reports that some users are receiving spam emails despite an email filter profile being applied to the SMTP traffic. The email filter profile has 'spam' action set to 'discard'. What is the most likely reason spam is still reaching users?
Medium153Which of the following security profiles is used to prevent malicious files from being downloaded via HTTP, FTP, or email by inspecting the content of the traffic?
Easy154What is the purpose of the 'safe search' option in a FortiGate web filter profile?
Easy155An organization uses Application Control to allow only business-critical applications and block social media. The administrator has configured the profile to block Facebook and Twitter, but users can still access Facebook. The firewall policy applies the profile correctly. What is the most likely cause?
Medium156A FortiGate administrator wants to block access to a list of known malicious websites. The list is updated frequently by a third-party threat intelligence feed. Which FortiGate feature should the administrator use to dynamically block these sites without manual intervention?
Easy157An administrator configures an email filter profile to block spam. Users complain that legitimate emails from a specific partner are being blocked. The admin wants to allow emails from that partner's domain without disabling spam filtering for other domains. What is the BEST approach?
Medium158Which security profile is used to detect and prevent network-based attacks by analyzing traffic patterns and comparing them against known attack signatures?
Easy159An administrator wants to ensure that all DNS traffic from internal users is filtered by the FortiGate to block malicious domains. Which TWO configurations are necessary? (Choose two.)
Medium160An administrator configures a web filter profile with FortiGuard category blocking and URL filter to allow example.com. Users report that example.com is still blocked. What is the most likely cause?
Medium161A network administrator notices that an IPS sensor is generating excessive false positives for a specific signature. The administrator wants to exclude traffic from a trusted internal server (IP 10.1.1.100) from inspection for that signature only, while keeping other signatures active. Which configuration change should the administrator apply?
Medium162An administrator has configured an IPS profile to detect SQL injection attacks. However, some SQL injection attempts are still reaching the web server. Which TWO actions should the administrator take to improve detection?
Hard163A FortiGate is configured with SSL deep inspection using a locally generated CA certificate. A user reports that they cannot access https://www.example.com and receive a certificate error. The administrator checks the firewall policy and sees that the SSL inspection profile is set to 'certificate-inspection' instead of 'deep-inspection'. What is the MOST likely effect?
Hard164A FortiGate administrator wants to block all traffic to a known malicious IP address range using the Intrusion Prevention System (IPS). Which IPS configuration method is most appropriate?
Medium165An administrator runs the CLI command 'diagnose debug rating' and sees that all FortiGuard web filter requests are timing out. What is the most likely cause?
Medium166A FortiGate receives a file via SMTP that contains a virus. The antivirus profile is set to 'Block' for viruses and the action is set to 'Quarantine'. However, the email is delivered to the user with the infected attachment. What could be the reason?
Hard167What is the difference between certificate inspection and full SSL deep inspection on a FortiGate?
Easy168An administrator wants to block users from uploading files to cloud storage services like Google Drive via HTTPS. Which security profile combination is required?
Hard169A FortiGate administrator needs to configure a policy so that traffic to a specific external server is exempted from SSL deep inspection. Which method should be used?
Hard170An administrator configures an application control profile to block social media applications. Users can still access Facebook and Twitter via web browsers. What is the most likely reason?
Medium171A FortiGate is configured with flow-based antivirus and an IPS profile on a policy. The administrator runs 'diagnose ips packet-list' and sees that packets are being forwarded without inspection. What is the most likely reason?
Hard172An administrator notices that traffic to a specific HTTPS website is being blocked. The FortiGate has SSL inspection enabled, and the web filter profile is set to monitor all categories. The URL is not in any blocked category. What should the administrator check next?
Hard173Which TWO types of inspection can be used for HTTPS traffic in a FortiGate security policy?
Easy174A FortiGate is configured for SSL deep inspection using a CA certificate. Users report that some websites show certificate errors. The administrator wants to allow these sites without inspection. Which setting should be used?
Medium175A FortiGate is configured with an IPS profile to detect and block anomalous network behavior. Which THREE types of detection does IPS anomaly detection include? (Choose three.)
Hard176An administrator runs 'diagnose ips anomaly list' and sees many 'tcp_syn_flood' entries. The IPS profile has anomaly detection enabled with action 'pass'. The administrator wants to block such attacks. What change is required?
Hard177An administrator configures an IPS profile to block SQL injection attacks. However, SQL injection traffic is still passing through the FortiGate. The administrator confirms the IPS profile is applied to the correct policy. What is the most likely reason?
Medium178A FortiGate administrator wants to integrate with FortiSandbox to analyze suspicious files detected by antivirus. The administrator configures the FortiSandbox settings under Security Fabric. However, files are not being sent to FortiSandbox. The antivirus profile is set to 'flow-based' inspection. What could be the reason?
Medium179What is the function of an IPS 'protocol decoder'?
Easy180An administrator applies an application control profile to a firewall policy that allows outbound traffic. Users report that a specific business-critical application, which uses TLS on port 443, is now being blocked even though the application is not listed as blocked in the profile. The administrator wants to allow this application while still controlling other applications. What is the most likely reason the application is being blocked?
Medium181A network administrator notices that HTTP traffic to a specific website is being blocked by the web filter profile, but the website is categorized as 'General – Personal' in FortiGuard, which is allowed. What could cause this block?
Medium182What is the primary difference between flow-based and proxy-based Antivirus inspection on a FortiGate?
EasyOther domains
All NSE4 exam domains
Frequently asked questions
- What does the Security Profiles domain cover on the NSE4 exam?
- Be able to configure and troubleshoot FortiGate security profiles, especially SSL inspection and web filtering. The single most important thing: ensure the FortiGate CA certificate is trusted on clients when using deep SSL inspection, or HTTPS sites will break.
- How many questions are in this domain?
- This page lists all 182 Security Profiles questions in the NSE4 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security Profiles questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.