Courseiva

CCNA Security Profiles Questions

75 of 182 questions · Page 1/3 · Security Profiles · Answers revealed

1
MCQhard

An administrator configures a DLP profile to detect credit card numbers in email traffic. The DLP rule uses a regular expression. However, the DLP sensor is not triggering on emails containing credit card numbers. What is a likely reason?

A.SSL deep inspection is not enabled on the policy
B.The regular expression is case-sensitive and credit card numbers are lowercase
C.The DLP sensor is configured to 'monitor' only
D.The DLP profile is applied to the inbound policy only
AnswerA

The FortiGate cannot inspect email content that is encrypted with TLS unless SSL deep inspection is enabled on the security policy. Without it, the device only sees the encrypted SMTP session, so DLP pattern matching never reads the credit card numbers in the payload. This is why the DLP profile appears to detect nothing despite being correctly configured.

Why this answer

DLP sensors inspecting email traffic require SSL deep inspection to decrypt the SMTP traffic if it is encrypted via TLS (STARTTLS). Without SSL deep inspection enabled on the firewall policy, the FortiGate cannot see the plaintext content of encrypted emails, so the DLP regular expression will never match credit card numbers. This is the most likely reason the DLP sensor is not triggering.

Exam trap

The trap here is that candidates assume DLP works on all traffic regardless of encryption, but Fortinet tests the understanding that SSL deep inspection is a prerequisite for DLP to inspect encrypted email content.

How to eliminate wrong answers

Option B is wrong because regular expressions in FortiGate DLP are case-insensitive by default, and credit card numbers are numeric, not alphabetic, so case sensitivity is irrelevant. Option C is wrong because a DLP sensor configured to 'monitor' only still triggers logging and can generate alerts; it does not prevent detection or matching. Option D is wrong because DLP profiles can be applied to both inbound and outbound policies, and even if applied only to inbound, emails containing credit card numbers would still be detected if they are inbound; the issue is encryption, not direction.

2
Multi-Selectmedium

A FortiGate administrator is configuring IPS to protect against a known exploit targeting a web server. The administrator wants to ensure that the IPS engine can decode the HTTP protocol. Which TWO actions are necessary?

Select 2 answers
A.Enable the HTTP protocol decoder in the IPS sensor
B.Configure an IP pool for the web server
C.Enable SSL deep inspection on the firewall policy
D.Set the IPS action to 'block'
E.Disable the FTP protocol decoder
AnswersA, C

The IPS engine uses protocol decoders to parse and normalize traffic into a structured format for signature matching. Without the HTTP decoder, the engine processes raw TCP segments and cannot interpret HTTP headers, URLs, or payloads, so HTTP-specific signatures won't trigger correctly. Enabling this decoder is mandatory for any meaningful HTTP inspection.

Why this answer

The HTTP protocol decoder must be enabled in the IPS sensor because the IPS engine uses protocol decoders to normalize traffic and apply signatures correctly. Without the HTTP decoder, the IPS engine cannot parse HTTP headers, methods, or URIs, making it blind to web-based exploits. This is a prerequisite for any HTTP-specific IPS inspection.

Exam trap

The trap here is that candidates often confuse the IPS action (block, monitor) with the enabling of protocol decoders, or assume SSL deep inspection alone is sufficient for HTTP inspection, when in fact both the HTTP decoder and SSL deep inspection are required for encrypted web traffic.

3
MCQhard

A FortiGate configured with IPS anomaly detection is generating false positives for the 'tcp_syn_flood' anomaly. The administrator wants to reduce the false positives without completely disabling the detection. Which action should the administrator take?

A.Disable the anomaly and use a custom IPS signature
B.Decrease the threshold value
C.Set the action to 'pass'
D.Increase the threshold value
AnswerD

Increasing the threshold value adjusts the anomaly's sensitivity so that a significantly larger rate of SYN packets per second is necessary to trigger the tcp_syn_flood anomaly. Legitimate connection bursts will now remain below the alarm level, avoiding false positives, while a genuine flood will still generate enough traffic to exceed the threshold and be blocked. This is the correct tune because it maintains an active defense while suppressing noise from normal traffic patterns.

Why this answer

Increasing the threshold value reduces false positives by requiring a higher rate of TCP SYN packets per second before the 'tcp_syn_flood' anomaly triggers an alert or action. This allows legitimate traffic bursts to pass without being flagged, while still detecting genuine SYN flood attacks. The threshold defines the sensitivity of the anomaly detection; raising it makes the detection less sensitive to low-volume spikes.

Exam trap

The trap here is that candidates often assume decreasing a threshold makes detection less sensitive (to reduce false positives), but in FortiGate anomaly detection, decreasing the threshold actually increases sensitivity, leading to more false positives.

How to eliminate wrong answers

Option A is wrong because disabling the anomaly and using a custom IPS signature would bypass the built-in anomaly detection entirely, which is not necessary and adds complexity; the goal is to reduce false positives, not replace detection. Option B is wrong because decreasing the threshold value makes the detection more sensitive, which would increase false positives, not reduce them. Option C is wrong because setting the action to 'pass' would disable all blocking or alerting for the anomaly, effectively ignoring the detection and not reducing false positives in a controlled manner.

4
MCQeasy

Which inspection mode allows FortiGate to perform virus scanning by reassembling the entire file in memory before scanning, providing better detection but potentially higher latency?

A.Fast-path inspection
B.Deep inspection
C.Proxy-based inspection
D.Flow-based inspection
AnswerC

Proxy-based inspection is the correct mode because it fully reassembles and buffers the entire file in memory before submitting it to the antivirus engine. This complete content capture enables sophisticated pattern matching and detection of threats that rely on whole-file context, at the expense of increased latency. For maximum virus detection assurance, FortiGate administrators use proxy-based inspection for antivirus profiles.

Why this answer

Proxy-based inspection is the FortiGate mode where the full file is buffered and reassembled in memory before the security profile (AV, IPS, etc.) inspects it. This allows complete-file scanning, so detection of threats that span multiple packets or require the whole file is far better, at the cost of added latency and memory usage. Flow-based inspection, by contrast, scans packets as they stream through, which is faster but can miss threats that only appear once the file is fully assembled.

Exam trap

NSE4 often tests the confusion between flow-based and proxy-based inspection, where candidates incorrectly assume flow-based mode reassembles the entire file — it does not; only proxy-based inspection buffers the full file in memory.

How to eliminate wrong answers

Option A is wrong because 'fast-path inspection' is not a FortiGate inspection mode — it refers to the accelerated path for traffic that bypasses UTM scanning, not a full-file scanning mode. Option B is wrong because 'deep inspection' is not a FortiGate proxy/flow mode; it describes the use of full SSL/TLS inspection (decrypting traffic) rather than the buffering behavior of proxy mode. Option D is wrong because flow-based inspection scans packets in-stream without reassembling the entire file in memory, so it offers lower latency but weaker detection than proxy-based inspection.

5
MCQhard

You run the following CLI command on a FortiGate: diagnose sys session filter dport 443 diagnose sys session list The output shows many sessions with 'proto=6 proto_state=01 duration=3600 expire=3599'. What does this indicate about the traffic?

A.The sessions are fully established and idle
B.The sessions are for UDP traffic
C.The sessions are being inspected by SSL deep inspection
D.The sessions are in the SYN_SENT state and have not completed the three-way handshake
AnswerD

The proto_state=01 in the session table is interpreted as SYN_SENT, meaning the TCP handshake has not completed. The FortiGate has sent (or received) a SYN and is waiting for the corresponding SYN-ACK to move to ESTABLISHED (proto_state=02). Because the session remains in proto_state=01, it correctly indicates that the sessions are in the SYN_SENT state and have not completed the three-way handshake.

Why this answer

The proto=6 indicates TCP, and proto_state=01 indicates a TCP session in the SYN_SENT state (i.e., the three-way handshake is not complete). The long duration suggests these are half-open sessions, possibly indicating a SYN flood attack.

6
Multi-Selecthard

An administrator wants to block all traffic from the 'P2P' application category but allow traffic from 'File Sharing' applications like Dropbox. Which THREE configurations are required to achieve this?

Select 3 answers
A.Create an application control profile that sets 'P2P' category to 'block' and 'File Sharing' category to 'allow'
B.Set the firewall policy inspection mode to proxy-based
C.Enable SSL/TLS deep inspection on the firewall policy
D.Ensure that the application control signatures are up to date
E.Apply a web filter profile to override the application control
AnswersA, C, D

Creating an application control profile with 'P2P' set to 'block' and 'File Sharing' set to 'allow' is the fundamental step because FortiOS application control categorizes traffic into distinct signatures. This configuration explicitly permits file-sharing protocols like FTP or SMB while denying peer-to-peer applications such as BitTorrent or eMule. Without this profile, no other setting can differentiate between these two categories.

Why this answer

An application control profile directly manages application categories, allowing you to set 'P2P' to 'block' and 'File Sharing' to 'allow'. This profile is then applied to a firewall policy to enforce the desired traffic filtering. Without this profile, the firewall cannot differentiate between these application categories.

Exam trap

The trap here is that candidates often assume proxy-based inspection is mandatory for application control, but FortiOS supports application control in both flow-based and proxy-based modes, making Option B a distractor.

7
MCQmedium

A school district uses a FortiGate to filter web traffic for students. The administrator wants to enforce that Google searches are filtered for explicit content. Which configuration should be applied?

A.Enable 'Google Safe Search' in the web filter profile under 'FortiGuard Categories' -> 'Safe Search'.
B.Use an application control profile to block the 'Google Search' application.
C.Create a URL filter to block URLs containing 'porn' or 'adult'.
D.Block the URL category 'Search Engines' and allow only approved search engines.
AnswerA

Enabling Google Safe Search in the web filter profile forces Google to return filtered results, blocking explicit content at the search engine itself. This satisfies the requirement to enforce filtered Google searches for students without inspecting every result page.

Why this answer

FortiGate's web filter profile includes a 'Safe Search' feature that enforces safe search on popular search engines like Google, Bing, and YouTube. Enabling 'Google Safe Search' under FortiGuard Categories -> Safe Search forces Google to return filtered results by modifying the search request to include the safe search parameter (e.g., 'safe=active'). This is the correct and granular way to enforce safe search without blocking search engines entirely.

Exam trap

NSE4 often tests the misconception that application control or URL filtering can enforce safe search, when in fact only the explicit Safe Search setting in the web filter profile performs this function.

How to eliminate wrong answers

Option B is wrong because application control blocks or allows applications based on signatures; blocking 'Google Search' would prevent all Google searches, not just filter explicit content. Option C is wrong because URL filtering based on keywords like 'porn' or 'adult' is easily bypassed and does not enforce safe search on search engine result pages. Option D is wrong because blocking the entire 'Search Engines' category and allowing only approved ones is overly restrictive and does not filter explicit content within allowed search engines.

8
MCQeasy

An administrator wants to block access to websites that host malware. Which FortiGate feature should be configured to achieve this goal?

A.IPS profile
B.DNS Filter profile
C.Application Control profile
D.Web Filtering profile with FortiGuard categories
AnswerD

A Web Filtering profile with FortiGuard categories is purpose-built for this task: it leverages FortiGuard's extensive web rating database to classify URLs into categories such as 'Malicious Web Sites' and applies a configurable action (block, warn, or allow) for each category. This profile evaluates the full URL at proxy level, enabling precise blocking of pages that host malware or phishing content.

Why this answer

FortiGate's Web Filtering profile with FortiGuard categories is the correct feature because it allows administrators to block access to websites based on URL categories, including those known to host malware. FortiGuard maintains a continuously updated database of malicious URLs, and applying a web filtering profile that blocks the 'Malicious Websites' category directly prevents users from accessing such sites. This is the most straightforward and effective method for blocking malware-hosting websites at the proxy or flow-based inspection level.

Exam trap

The trap here is that candidates often confuse DNS Filtering (which blocks domains at the DNS level) with Web Filtering (which blocks URLs at the HTTP/HTTPS level), but DNS Filtering cannot block specific URL paths or subdirectories, making it insufficient for blocking malware-hosting websites that may share a domain with legitimate content.

How to eliminate wrong answers

Option A is wrong because an IPS profile is designed to detect and prevent network-based attacks by inspecting traffic for exploit signatures, not to block access to specific websites or URL categories. Option B is wrong because a DNS Filter profile controls access based on domain name resolution, blocking or redirecting DNS queries to known malicious domains, but it does not inspect the full URL path or HTTP content, and it is not the primary feature for blocking malware-hosting websites. Option C is wrong because an Application Control profile identifies and controls applications (e.g., social media, file sharing) based on signatures, not URLs or web categories, so it cannot block specific websites hosting malware.

9
MCQmedium

An administrator wants to prevent data leakage by blocking outbound emails that contain credit card numbers. Which security profile should be configured?

A.Email Filter profile
B.Web Filter profile
C.Antivirus profile
D.DLP profile
AnswerD

A DLP profile inspects email content for sensitive data patterns, such as credit card numbers, and blocks matching messages. This directly satisfies the stem's requirement to prevent data leakage via outbound email, since DLP is the only FortiGate profile that performs content-based pattern matching on data rather than application or protocol control.

Why this answer

DLP (Data Loss Prevention) profiles are specifically designed to inspect content such as credit card numbers in outbound emails and block them to prevent data leakage. While other profiles handle spam, web access, or malware, only DLP can perform pattern-based content inspection on email bodies and attachments.

Exam trap

The trap here is that candidates often confuse DLP with Email Filter or Antivirus profiles, not realizing that DLP is the only profile that performs content-aware inspection for sensitive data patterns in outbound emails.

How to eliminate wrong answers

Option A is wrong because an Email Filter profile is used for anti-spam, email authentication (SPF/DKIM/DMARC), and IP reputation filtering, not for scanning email content for sensitive data patterns like credit card numbers. Option B is wrong because a Web Filter profile controls web access based on URL categories and ratings, not email content inspection. Option C is wrong because an Antivirus profile scans for malware signatures in files and email attachments, but does not perform content-based pattern matching for sensitive data like credit card numbers.

10
MCQhard

A FortiGate is configured with an SSL deep inspection profile that uses 'Certificate Inspection' (not 'Full SSL Inspection'). Which of the following is TRUE about this configuration?

A.Deep inspection can still see client certificates
B.The antivirus profile can scan the HTTPS payload
C.The FortiGate can block HTTPS connections based on the certificate's CN
D.IPS can still inspect the application layer of HTTPS traffic
AnswerC

During the TLS handshake, the server's certificate is sent in plaintext, and certificate inspection extracts the Common Name (CN) and Subject Alternative Name (SAN) to make web filtering decisions. The FortiGate can therefore block or allow an HTTPS request before any application data is exchanged, using the certificate's CN as the classification criterion even with no decryption.

Why this answer

Certificate Inspection only examines the SSL/TLS certificate presented during the handshake, without decrypting the traffic. Because the FortiGate can read the certificate's Common Name (CN) or Subject Alternative Name (SAN), it can block HTTPS connections based on that information, such as by using a URL filter or application control rule that matches the certificate's CN. This is the only deep inspection action possible without full decryption.

Exam trap

The trap here is that candidates often assume 'deep inspection' implies full decryption, but Fortinet distinguishes between Certificate Inspection (no decryption) and Full SSL Inspection (decryption), and the question specifically tests this distinction by asking what is possible without decryption.

How to eliminate wrong answers

Option A is wrong because Certificate Inspection does not decrypt the SSL session, so it cannot see client certificates, which are sent encrypted after the handshake. Option B is wrong because the antivirus profile requires decrypted payload to scan for malware, and Certificate Inspection does not provide decrypted content. Option D is wrong because IPS inspection of the application layer requires full decryption of the HTTPS traffic, which Certificate Inspection does not perform.

11
MCQmedium

A FortiGate administrator configures an email filter profile to block spam. Users report that some legitimate emails are being blocked. The administrator wants to reduce false positives while still blocking spam. What should the administrator do?

A.Disable the email filter profile
B.Increase the spam threshold score
C.Decrease the spam threshold score
D.Enable the FortiGuard spam filter only
AnswerB

The spam threshold score defines the rating at which a message is classified as spam. Raising it means messages must score higher before being blocked, so borderline legitimate emails pass through while clear spam is still caught, reducing false positives.

Why this answer

Increasing the spam threshold score raises the bar for what is classified as spam, so only emails with a higher spam score (indicating stronger spam characteristics) are blocked. This reduces false positives because legitimate emails with lower scores will no longer be blocked, while still blocking high-scoring spam.

Exam trap

The trap here is that candidates often confuse increasing vs. decreasing the threshold, mistakenly thinking a lower threshold is more permissive, when in fact a lower threshold blocks more emails and increases false positives.

How to eliminate wrong answers

Option A is wrong because disabling the email filter profile would stop all spam filtering, which does not address the requirement to reduce false positives while still blocking spam. Option C is wrong because decreasing the spam threshold score would make the filter more aggressive, blocking more emails and likely increasing false positives. Option D is wrong because enabling only the FortiGuard spam filter does not adjust the sensitivity of the filter; it simply changes the source of spam detection, which may not reduce false positives and could still block legitimate emails.

12
MCQhard

A FortiGate is configured with flow-based inspection and an IPS profile. The administrator runs 'diagnose ips session list' and sees many sessions with 'state=bypass'. What does this indicate?

A.The IPS profile is configured with 'pass' action for all signatures
B.The IPS signatures have expired and are not being applied
C.The FortiGate is under DoS attack and is dropping sessions
D.The sessions are being offloaded to the NPU and are not inspected by IPS
AnswerD

In flow-based inspection mode, the FortiGate offloads many sessions to the NPU for high-throughput processing. When a session is offloaded, packets traverse the NPU and are not sent to the CPU, so the IPS engine never inspects them; the session is then marked as 'bypass'. This is expected behavior for traffic that is not explicitly selected for deep inspection, and it explains why the IPS engine reports no inspection. Admins can confirm this by checking the session table via 'diagnose sys session list'.

Why this answer

When a FortiGate uses flow-based inspection, sessions that are offloaded to the Network Processor Unit (NPU) are not inspected by the IPS engine. The 'state=bypass' in the 'diagnose ips session list' output indicates that these sessions are being hardware-accelerated and bypassing the IPS inspection, which is normal behavior for traffic that meets offload criteria.

Exam trap

The trap here is that candidates often misinterpret 'bypass' as a failure or misconfiguration, when in fact it is a normal operational state for hardware-accelerated sessions in flow-based mode.

How to eliminate wrong answers

Option A is wrong because a 'pass' action in an IPS profile means the signature will allow the traffic but still log it; it does not cause sessions to show 'state=bypass' in the IPS session list. Option B is wrong because expired IPS signatures would cause the IPS engine to stop applying signatures entirely, not result in a bypass state for individual sessions. Option C is wrong because a DoS attack would cause session drops or blocks, not a bypass state; the 'bypass' state specifically indicates the session is not being inspected, not that it is being dropped.

13
MCQeasy

Which two inspection modes are available for antivirus scanning on a FortiGate?

A.Stateful and stateless
B.Flow-based and proxy-based
C.Inline and passive
D.Kernel-based and user-based
AnswerB

Flow-based and proxy-based are the two security profile inspection modes supported on FortiGate for antivirus and other UTM features. Flow mode performs scanning in a single pass directly on packets transiting the kernel and can be accelerated by FortiASIC content processors (CP), lowering latency and supporting high-throughput links. Proxy mode terminates the TCP session in a dedicated proxy engine, reassembles and buffers the full content before scanning, enabling deeper inspection of files and more granular control at the cost of higher latency and resource consumption.

Why this answer

FortiGate offers two distinct inspection modes for antivirus scanning: flow-based and proxy-based. Flow-based inspection uses a single-pass, low-latency engine that examines traffic as it passes through, while proxy-based inspection buffers and reassembles the entire file before scanning, providing deeper analysis at the cost of higher latency. Both modes are configured within the antivirus security profile to match different performance and security requirements.

Exam trap

The trap here is that candidates confuse firewall inspection modes (stateful/stateless) or IDS/IPS deployment modes (inline/passive) with the two antivirus scanning modes, which are specifically flow-based and proxy-based on FortiGate.

How to eliminate wrong answers

Option A is wrong because 'stateful and stateless' refer to firewall inspection modes (stateful tracking of connections vs. stateless packet filtering), not to antivirus scanning modes. Option C is wrong because 'inline and passive' describe deployment modes for intrusion detection/prevention systems (IDS/IPS), where inline can block traffic and passive only monitors; these are not antivirus scanning modes on FortiGate. Option D is wrong because 'kernel-based and user-based' are not recognized inspection modes for antivirus on FortiGate; the actual modes are flow-based (kernel-level acceleration) and proxy-based (user-space processing), but the official terminology is flow-based and proxy-based.

14
Multi-Selecthard

Which TWO statements about IPS in FortiGate are true?

Select 2 answers
A.IPS can be applied to individual firewall policies via IPS sensors.
B.An IPS sensor can only be applied to one firewall policy.
C.IPS is not supported in transparent mode.
D.IPS only works in flow-based inspection mode.
E.IPS signatures can have their actions overridden in an IPS filter.
AnswersA, E

In FortiGate, IPS is enforced at the firewall policy level by assigning an IPS sensor to the policy's Security Profiles. This design lets each policy pass traffic through the sensor's configured signature rules, enabling selective inspection for different source/destination pairs. Because a sensor is a reusable object, the same sensor can be applied to any number of policies, and changes to the sensor immediately affect all policies referencing it.

Why this answer

IPS sensors are applied directly to individual firewall policies, allowing granular control over which traffic is inspected for intrusions. This enables administrators to enforce different IPS profiles for different traffic flows, such as applying a stricter sensor to internet-bound traffic and a lighter one to internal traffic.

Exam trap

The trap here is that candidates often assume IPS requires routed mode or flow-based inspection only, but FortiGate supports IPS in transparent mode and in both inspection modes, and sensors are reusable across multiple policies.

15
Matchingmedium

Match each Fortinet HA mode to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

One unit handles traffic; standby unit takes over on failure

Both units handle traffic simultaneously for load balancing

Multiple units act as a single logical firewall

Ensures active sessions are preserved after failover

FortiGate Clustering Protocol used for HA synchronization

Why these pairings

Common FortiGate HA modes: Active-Passive (primary/standby) and Active-Active (both active). Distractors swap the definitions.

16
Multi-Selecteasy

Which TWO are valid types of SSL/TLS inspection available on FortiGate?

Select 2 answers
A.Off-box SSL Inspection
B.Proxy SSL Inspection
C.Full SSL Deep Inspection
D.Passive SSL Inspection
E.Certificate Inspection
AnswersC, E

Full SSL Deep Inspection is a valid and correct FortiGate SSL inspection type. It decrypts SSL/TLS traffic in real time, inspects the plaintext content against security policies such as antivirus, web filtering, and intrusion prevention, then re-encrypts it before forwarding. This provides complete visibility into encrypted traffic, making it the most thorough inspection option, but it requires clients to trust the FortiGate's CA certificate to avoid errors.

Why this answer

FortiGate supports two primary SSL/TLS inspection methods: Certificate Inspection, which validates certificates without decrypting traffic, and Full SSL Deep Inspection, which decrypts, inspects, and re-encrypts traffic to apply security profiles. Option C is correct because Full SSL Deep Inspection is the only method that allows the FortiGate to inspect the payload of encrypted sessions for threats like malware or data leakage.

Exam trap

The trap here is that candidates often confuse 'Proxy SSL Inspection' with the proxy-based inspection mode, but FortiGate officially lists only Certificate Inspection and Full SSL Deep Inspection as the valid types, and 'Off-box' or 'Passive' are not recognized terms in the FortiGate SSL inspection architecture.

17
MCQmedium

A mid-sized company has a FortiGate 100F running FortiOS 7.2. They have two internal networks: Trusted (10.1.1.0/24) for employees and Guest (10.2.2.0/24) for visitors. The Guest network has a firewall policy that allows internet access only, with an application control profile that blocks all peer-to-peer and gaming applications. Recently, users on the Guest network have been able to play online games (e.g., Fortnite) despite the block. The administrator checks the application control profile and confirms that 'Fortnite' is listed as blocked. There are no other policies allowing Guest traffic. The administrator also notices that the Guest policy has 'set utm-status enable' and the application control profile is applied. What is the most likely reason that Fortnite is not being blocked?

A.The firewall policy is missing 'set deep-inspection enable' for application control to work.
B.SSL inspection is required to block encrypted game traffic, and it is not enabled.
C.The application control profile is not applied to the correct policy.
D.The application control signatures are outdated and do not include the latest Fortnite signatures.
AnswerD

Newer game traffic, such as Fortnite, uses frequently changing update servers and protocols, so a FortiGate with an outdated FortiGuard signature database will fail to match those flows. Application control relies on regularly updated signatures to identify application-specific traffic patterns and unblocked domains. If the signature version predates a major Fortnite update, the traffic is passed as unknown. The solution is to update the FortiGuard application control signatures (either manually or via scheduled updates) and then retest the Guest policy.

Why this answer

If the Application Control signatures are outdated, the FortiGate may not recognize the latest Fortnite traffic patterns or encrypted handshakes, allowing the game to bypass the block. Even though the policy has UTM enabled and the profile is applied, stale signatures cannot match new application variants or updates. Regularly updating the IPS/Application Control database via FortiGuard is essential to maintain effective blocking.

Exam trap

The trap here is that candidates often assume SSL inspection is mandatory for blocking encrypted applications, but the real issue is that outdated signatures fail to recognize the latest application variants, even when the profile is correctly applied and UTM is enabled.

How to eliminate wrong answers

Option A is wrong because 'set deep-inspection enable' is not a valid command for firewall policies; deep inspection is configured via SSL/SSH inspection profiles, not a direct policy flag, and Application Control can work without full SSL inspection if the game uses non-encrypted or partially encrypted traffic. Option B is wrong because while SSL inspection can help identify encrypted game traffic, it is not strictly required for Application Control to block applications; many games use plaintext or proprietary protocols that signatures can match without decryption, and the question states the profile already blocks Fortnite, indicating the issue is signature freshness, not inspection depth. Option C is wrong because the administrator already confirmed the Application Control profile is applied to the Guest policy, and there are no other policies allowing Guest traffic, so the profile is correctly attached.

18
MCQmedium

A FortiGate administrator wants to block spam emails destined for internal users. The FortiGate receives SMTP traffic on port 25. What is the most effective way to filter spam using the email filter profile?

A.Enable spam filtering in the antivirus profile
B.Apply an email filter profile to a firewall policy that allows SMTP traffic
C.Use a DNS filter to block spam domains
D.Configure a web filter to block webmail
AnswerB

For inbound SMTP, the correct procedure is to create a firewall policy for the SMTP service and attach an email filter profile to that policy; the FortiOS inspection engine then applies FortiGuard Antispam category lookups, IP/DNSBL checks, header and MIME analysis, and banned-word rules to every accepted email. The email filter profile is the sole UTM object that contains antispam capabilities, and it is designed to operate on mail protocols (SMTP, POP3, IMAP) in proxy-based inspection mode. This policy-level attachment is exactly how a FortiGate administrator activates spam blocking in production.

Why this answer

An email filter profile is specifically designed to inspect SMTP traffic and apply anti-spam techniques such as RBL, MIME header checks, and heuristic analysis. By applying the email filter profile to a firewall policy that allows SMTP traffic on port 25, the FortiGate can intercept and filter spam before it reaches internal users.

Exam trap

The trap here is that candidates often confuse the email filter profile with the antivirus profile, assuming antivirus handles all email threats, but antivirus only scans for malware, not spam.

How to eliminate wrong answers

Option A is wrong because the antivirus profile scans for malware signatures in file attachments, not for spam characteristics like bulk email patterns or sender reputation. Option C is wrong because a DNS filter blocks access to domains based on category or reputation, but it does not inspect the content or headers of SMTP messages to identify spam. Option D is wrong because a web filter controls HTTP/HTTPS traffic to block webmail sites, but it does not filter SMTP-based spam arriving on port 25.

19
Matchingmedium

Match each FortiGate firewall policy action to its result.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Allows traffic matching the policy

Blocks traffic and sends a reset or ICMP unreachable

Routes traffic into an IPsec VPN tunnel

Routes traffic into an SSL VPN tunnel

Logs traffic without enforcing action (used for learning)

Why these pairings

The correct matches are ACCEPT for allowing traffic and DENY for silently dropping traffic. Common confusions include mixing ACCEPT with REJECT (which sends a reset) and assuming DENY logs traffic.

20
Multi-Selecthard

A FortiGate administrator is troubleshooting an issue where a user receives a certificate error when accessing a web server. The administrator has configured SSL deep inspection with a custom CA certificate. The error indicates the certificate is not trusted. Which THREE actions could resolve this issue? (Choose three.)

Select 3 answers
A.Install the FortiGate's CA certificate on the client devices.
B.Disable SSL inspection on the firewall policy entirely.
C.Update the FortiGate firmware to the latest version.
D.Change the SSL inspection profile to 'certificate-inspection' instead of 'deep-inspection'.
E.Add the web server to the SSL exemption list in the SSL inspection profile.
AnswersA, D, E

Deep inspection performs man-in-the-middle interception, presenting a dynamically generated certificate signed by the FortiGate's own CA to the client. If that CA is not in the client's trusted root store, the browser reports a certificate error. Installing the FortiGate's CA certificate on client devices establishes trust for all re-issued certificates, which resolves the error while preserving full inspection of the decrypted payload.

Why this answer

Option A is correct because with SSL deep inspection the FortiGate re-signs the server certificate using its custom CA, so that CA certificate must be imported into the client's trust store (e.g., Windows Certificate Manager or browser trust store) for the re-signed certificate to validate without an untrusted-CA error. Option D is correct because switching the profile to certificate-inspection means the FortiGate only inspects the certificate metadata (SNI, CN, validity) and does not re-sign the server certificate, so the client sees the original, publicly trusted server certificate and no trust error occurs. Option E is correct because adding the web server to the SSL exemption list in the inspection profile bypasses deep inspection for that destination, again letting the client receive the original trusted certificate.

Option B is not the intended fix because disabling SSL inspection entirely removes security inspection rather than resolving the trust problem while preserving inspection. Option C is not relevant because a firmware update does not make the client trust the FortiGate's custom CA certificate or change the re-signing behavior.

Exam trap

NSE4 often tests the misconception that simply enabling deep inspection is enough, forgetting that the client must trust the FortiGate's CA — or that certificate-inspection and exemption are valid alternatives when deep inspection is not feasible.

21
MCQmedium

An administrator is configuring email filtering on FortiGate to block spam. Which of the following is required for FortiGate to filter inbound email directly?

A.FortiMail must be deployed as a separate appliance
B.The FortiGate must be configured as an SMTP proxy
C.SSL deep inspection must be enabled for SMTP traffic
D.The email filtering profile must be applied to a policy covering port 110
AnswerB

The FortiGate must be configured to operate as an SMTP proxy in the security policy to intercept and filter email traffic on port 25. In this proxy mode, the FortiGate acts as a relay that receives, inspects, and forwards email, allowing the UTM email filter and antivirus profiles to examine the message body, headers, and attachments. This is the standard method to apply email filtering on FortiGate; without proxy mode, the device would only see IP and port information, not the mail content.

Why this answer

FortiGate can filter inbound email directly only when it is configured as an SMTP proxy, which allows it to intercept and inspect SMTP traffic at the application layer. This proxy mode enables the FortiGate to apply email filtering profiles, including anti-spam and antivirus, to SMTP sessions without requiring a separate appliance.

Exam trap

The trap here is that candidates often assume FortiGate requires a separate FortiMail appliance for any email filtering, but FortiGate's SMTP proxy feature provides direct inbound email filtering without additional hardware.

How to eliminate wrong answers

Option A is wrong because FortiMail is a dedicated email security gateway, but FortiGate can perform SMTP-based email filtering natively without needing FortiMail as a separate appliance. Option B is wrong because it is actually the correct answer, not a wrong option. Option C is wrong because SSL deep inspection is not required for SMTP filtering; FortiGate can filter SMTP traffic in plaintext or with opportunistic TLS without full SSL inspection.

Option D is wrong because port 110 (POP3) is used for email retrieval, not inbound SMTP delivery; email filtering for inbound mail must be applied to a policy covering SMTP on port 25.

22
MCQhard

A FortiGate administrator runs the command 'diagnose application urlfilter 0 status' and sees 'status: enable' but users report that some malicious URLs are not blocked. The web filter profile uses FortiGuard categories with 'block' action. What should the administrator check next?

A.The antivirus profile is blocking URL filtering
B.The FortiGuard web filter rating service is reachable
C.The DNS filter is overriding the web filter
D.The firewall policy is set to 'accept' without inspection
AnswerB

For web filtering to function, the FortiGate must be able to contact the FortiGuard rating service to obtain URL category information. When the rating service is unreachable, the FortiGate may fall back to local cached ratings or fail open, allowing all URLs to pass if no local rating exists. Therefore, checking connectivity to FortiGuard servers is a primary diagnostic step. This is the correct explanation because without reachability, real-time URL categorization cannot occur.

Why this answer

The 'diagnose application urlfilter 0 status' command shows that the URL filter process is enabled locally, but if the FortiGate cannot reach the FortiGuard rating service, it cannot retrieve category ratings for URLs. Without a valid rating, the device may allow malicious URLs by default (depending on the 'unrated' action), even if the profile is set to block certain categories. Option B is correct because checking the reachability of the FortiGuard web filter rating service is the logical next step to diagnose why categories are not being enforced.

Exam trap

The trap here is that candidates assume 'status: enable' means the web filter is fully operational, but they overlook that the FortiGuard rating service must be reachable for category-based blocking to work; the exam tests whether you understand the difference between the local filter process being enabled and the external rating service being available.

How to eliminate wrong answers

Option A is wrong because antivirus profiles do not block URL filtering; they scan files for malware and operate independently of web filter category blocking. Option C is wrong because DNS filtering controls access based on domain reputation and can coexist with web filtering, but it does not override the web filter's category-based blocking; the issue is that categories are not being applied at all. Option D is wrong because if the firewall policy were set to 'accept' without inspection, no web filtering would occur at all, but the administrator already confirmed the URL filter status is 'enable', indicating inspection is configured; the problem is that the rating service is unreachable, not that inspection is missing.

23
MCQeasy

Which security profile type requires a FortiSandbox license to enable advanced detection features?

A.Application Control
B.DNS Filter
C.Antivirus
D.Web Filter
AnswerC

Antivirus profile is the correct answer because FortiSandbox integration is a feature of the antivirus security profile in FortiOS. When an antivirus profile encounters an unknown file, it can send a copy to FortiSandbox for advanced static and dynamic analysis if the FortiSandbox license is available. This extends the signature-based antivirus capability to detect zero-day and advanced persistent threats. Without a license, the AV profile still scans using FortiGuard signatures, but cannot offload files to sandbox.

Why this answer

The Antivirus security profile (Option C) is correct because FortiGate's advanced antivirus features, such as outbreak prevention and cloud-based pattern matching, require a FortiSandbox license to offload suspicious files for dynamic analysis. Without this license, the antivirus engine relies solely on local signatures and cannot leverage sandboxing for zero-day threat detection.

Exam trap

The trap here is that candidates often assume all security profiles can leverage FortiSandbox for advanced detection, but only the Antivirus profile requires the license to enable its core advanced features like outbreak prevention and cloud-based pattern matching.

How to eliminate wrong answers

Option A is wrong because Application Control uses signatures and behavioral heuristics to identify applications, and its advanced features (e.g., cloud-based application database updates) do not require a FortiSandbox license. Option B is wrong because DNS Filter relies on FortiGuard DNS reputation and category databases, not sandbox analysis, to block malicious domains. Option D is wrong because Web Filter uses URL categorization and rating from FortiGuard, and while it can integrate with FortiSandbox for URL rating, the core filtering function does not require a sandbox license.

24
MCQhard

A FortiGate is configured with SSL inspection and web filtering. The administrator notices that some HTTPS traffic is being blocked even though the URL is in an allowed category. What could be the cause?

A.The FortiGate's DNS server is not resolving the domain correctly.
B.The web filter's 'allow' list is misconfigured.
C.The web filter profile has 'safe-search' enabled.
D.The SSL inspection profile has 'certificate-validation-failed' action set to 'block'.
AnswerD

When an SSL inspection profile has the 'certificate-validation-failed' action set to 'block', the FortiGate actively terminates the TLS handshake whenever the server certificate fails validation, such as due to an expired certificate, an untrusted CA, or a hostname mismatch. This action is evaluated during the SSL inspection proxy phase, before any decrypted content is passed to the web filter for URL categorisation. Consequently, the user sees a connection reset or block page even though the web filter profile itself may have no rule blocking the URL. This direct cause-and-effect matches the scenario exactly.

Why this answer

When SSL inspection is enabled, the FortiGate acts as a man-in-the-middle and validates the server's certificate. If the certificate is invalid (e.g., expired, self-signed, or mismatched), the FortiGate can block the session based on the 'certificate-validation-failed' action in the SSL inspection profile. Even if the URL belongs to an allowed web filter category, a failed certificate validation will cause the traffic to be blocked before the web filter policy is applied.

Exam trap

The trap here is that candidates often assume web filtering categories alone control HTTPS traffic, forgetting that SSL inspection's certificate validation can preemptively block sessions even for allowed URLs.

How to eliminate wrong answers

Option A is wrong because DNS resolution issues would prevent the FortiGate from reaching the server at all, but the symptom here is that HTTPS traffic is blocked specifically, not that the domain is unreachable. Option B is wrong because the 'allow' list being misconfigured would affect all traffic, not just HTTPS, and the question states the URL is in an allowed category, so the web filter should permit it. Option C is wrong because 'safe-search' enforces search engine restrictions (e.g., Google SafeSearch) and does not block entire HTTPS sessions; it modifies search queries, not certificate validation.

25
MCQeasy

What is the purpose of enabling 'Safe Search' in a web filter profile on a FortiGate?

A.It blocks all searches containing the word 'safe'.
B.It redirects users to a safe landing page when a blocked site is accessed.
C.It forces search engines to filter explicit content from search results.
D.It encrypts search queries to protect user privacy.
AnswerC

Enabling Safe Search on a FortiGate instructs the device to enforce the SafeSearch parameter on supported platforms like Google, Bing, and Yahoo, forcing those engines to exclude adult and explicit material from query results. This is accomplished through URL parameter injection or API calls when the user's request is inspected, typically requiring HTTPS inspection to see and modify the query. It ensures that even if a user manually attempts to disable safe search in the browser, the security policy overrides the setting. This filtering shields users from pornography and violent content appearing directly in search result listings.

Why this answer

Safe Search in a FortiGate web filter profile forces supported search engines (e.g., Google, Bing, Yahoo) to filter explicit content from search results by appending specific URL parameters (e.g., `&safe=active` for Google) to search queries. This ensures that when users perform searches, the search engine's own safe search setting is enforced at the network level, preventing access to adult or inappropriate material regardless of the user's browser settings.

Exam trap

The trap here is that candidates often confuse Safe Search with URL filtering or block pages, thinking it blocks or redirects users, rather than understanding it modifies search engine parameters to filter content at the source.

How to eliminate wrong answers

Option A is wrong because Safe Search does not block searches containing the word 'safe'; it modifies search engine behavior to filter explicit content. Option B is wrong because redirecting users to a safe landing page when a blocked site is accessed is the function of a block message or replacement message, not Safe Search. Option D is wrong because Safe Search does not encrypt search queries; encryption of web traffic is handled by SSL/HTTPS inspection or VPN policies, not by the web filter profile's Safe Search feature.

26
MCQeasy

Which security profile is used to detect and prevent spam email messages?

A.DLP profile
B.Web filter profile
C.Email filter profile
D.Antivirus profile
AnswerC

The email filter profile is the dedicated antispam engine within FortiGate, combining sender IP/domain blacklists, DNS-based blocklists, and real-time content analysis with ML-based classification. It inspects SMTP sessions by examining the message envelope, MIME headers, and body against a library of spam signatures and heuristics, while also performing Sender Policy Framework, DKIM, and DMARC verification. This profile can automatically quarantine, tag, or drop unwanted messages, making it the correct choice for spam detection.

Why this answer

The Email Filter profile is specifically designed to detect and prevent spam by analyzing SMTP traffic, applying techniques such as DNS-based Blackhole Lists (DNSBL), email reputation filtering, and heuristic analysis to identify unsolicited bulk email. Unlike other security profiles, it operates at the application layer for email protocols (SMTP, POP3, IMAP) to enforce anti-spam policies.

Exam trap

The trap here is that candidates confuse the Email Filter profile with the Antivirus profile, assuming spam detection is part of malware scanning, but FortiGate separates these functions: Antivirus handles file-based threats, while Email Filter handles message-based classification.

How to eliminate wrong answers

Option A is wrong because DLP (Data Loss Prevention) profiles focus on detecting and blocking sensitive data (e.g., credit card numbers, PII) in transit or at rest, not on identifying spam patterns or email content classification. Option B is wrong because Web Filter profiles control HTTP/HTTPS traffic by categorizing URLs and blocking malicious or inappropriate websites, but they do not inspect email message headers or bodies for spam characteristics. Option D is wrong because Antivirus profiles scan for malware signatures and heuristics in files and attachments, but they lack the specific anti-spam engines (e.g., Bayesian filtering, greylisting) needed to detect unsolicited bulk email.

27
MCQmedium

A FortiGate administrator needs to prevent employees from using peer-to-peer file sharing applications such as BitTorrent. The administrator creates an application control profile with a rule to block the 'Peer-to-Peer' application category. After applying the profile to the firewall policy, users can still use BitTorrent. What is the most likely cause?

A.The application control profile is applied to the outbound policy but not to the inbound policy.
B.The application control profile is set to 'Monitor' instead of 'Block' for the Peer-to-Peer category.
C.BitTorrent is not a recognized application in the FortiGuard application control database.
D.The firewall policy has SSL inspection set to certificate inspection, so the FortiGate cannot see the application.
AnswerB

In FortiOS, an application control profile defines per-category actions such as Monitor, Allow, or Block. If the Peer-to-Peer category is left as 'Monitor', the FortiGate identifies BitTorrent, writes a log entry, but still forwards the packets, so employees can keep using it. Only changing the action to 'Block' (or adding a specific BitTorrent rule with block) will actually deny the traffic. Thus, the correct fix is to edit the profile's Peer-to-Peer setting to enforce blocking rather than merely monitoring.

Why this answer

In FortiGate application control, each application category can be set to 'Block', 'Monitor', or 'Allow'. If the administrator creates a profile with a rule for the 'Peer-to-Peer' category but leaves the action as 'Monitor' (the default in some cases), the FortiGate will only log the traffic and not block it. Therefore, users can still use BitTorrent.

The most likely cause is that the action is set to Monitor instead of Block.

Exam trap

NSE4 often tests the default action of application control rules, and candidates may assume that adding a category to a profile automatically blocks it, when in fact the action must be explicitly set to Block.

How to eliminate wrong answers

Option A is wrong because application control is typically applied to the outbound policy that carries the user traffic; applying it to the inbound policy is not required to block outbound P2P usage, and the question states the profile was applied to the firewall policy. Option C is wrong because BitTorrent is a well-known application in the FortiGuard database, so it is recognized. Option D is wrong because application control can identify P2P applications using deep packet inspection even with certificate inspection for SSL, though full SSL inspection may be needed for some encrypted P2P; however, the question's scenario does not indicate SSL inspection is the blocker, and the most direct cause is the action setting.

28
Multi-Selectmedium

An administrator is configuring web filtering on a FortiGate. Which TWO statements about web filtering profiles are correct?

Select 2 answers
A.Web filtering profiles can be used together with application control profiles.
B.Web filtering profiles can only be applied to users who are authenticated.
C.Web filtering profiles can block access to websites based on URL categories and ratings.
D.Web filtering profiles are applied globally by default.
E.Web filtering profiles are used to configure SSL certificate inspection.
AnswersA, C

On FortiGate, web filtering and application control profiles are complementary UTM features that can both be inserted into the same firewall policy. A web filtering profile evaluates HTTP/HTTPS requests against URL categories and FortiGuard ratings, while an application control profile identifies and controls the applications traversing the network, regardless of the URL used. This allows you to block, for example, a URL category while simultaneously allowing or restricting the specific applications that the traffic uses.

Why this answer

Web filtering profiles and application control profiles operate independently at different layers of the FortiGate security fabric. Web filtering inspects HTTP/HTTPS traffic against URL categories and ratings, while application control identifies and controls application-level traffic (e.g., Facebook, Skype) using deep packet inspection. They can be applied together in a single security policy to provide layered protection without conflict.

Exam trap

The trap here is that candidates often confuse the scope of web filtering profiles, assuming they require authentication (B) or are global by default (D), or they mistakenly think SSL inspection is configured within the web filtering profile (E) instead of as a separate inspection profile.

29
MCQeasy

Refer to the exhibit. An administrator has configured the SSL/SSH profile shown. However, users are unable to access HTTPS websites. What is the most likely cause?

A.The 'untrusted-caname' should be set to a trusted CA certificate to handle untrusted server certificates.
B.The port is set to 443, but HTTPS also uses port 8443.
C.The 'caname' is set to 'Fortinet_CA_SSL', which is not a valid certificate name.
D.The 'whitelist-mode' is disabled, which prevents inspection.
AnswerA

In FortiGate SSL inspection profiles, the 'untrusted-caname' parameter specifies a CA certificate used to re-sign server certificates that are not already trusted by the FortiGate, such as self-signed or internally issued certificates. If this field is left blank or points to an untrusted CA, the FortiGate will fall back to a default CA that clients do not recognize, causing certificate validation warnings and potential connection failures in web browsers. To ensure seamless inspection of sites with untrusted server certificates, the administrator must assign a trusted CA—typically the FortiGate's built-in CA or a corporate CA—so clients accept the re-signed certificates without alerts.

Why this answer

When the SSL/SSH profile has 'untrusted-caname' set to 'Fortinet_CA_SSL' (an untrusted CA), the FortiGate cannot re-sign certificates from untrusted servers with a trusted CA. This causes HTTPS websites to fail as the client receives an untrusted certificate warning or connection error. Setting 'untrusted-caname' to a trusted CA certificate ensures that even untrusted server certificates are re-signed with a certificate the client trusts.

Exam trap

The trap here is that candidates confuse the 'caname' and 'untrusted-caname' fields, assuming any CA name is sufficient, without understanding that the CA must be trusted by the client for the re-signed certificate to be accepted.

How to eliminate wrong answers

Option B is wrong because HTTPS uses port 443 by default, and the profile is configured for port 443; port 8443 is an alternative HTTPS port but not required for standard HTTPS access. Option C is wrong because 'Fortinet_CA_SSL' is a valid default certificate name used by FortiGate for SSL inspection; the issue is not the name but its trust status. Option D is wrong because 'whitelist-mode' being disabled is the default and does not prevent inspection; it simply means all traffic is inspected unless explicitly whitelisted.

30
MCQmedium

A network administrator is troubleshooting why certain web-based applications are not being identified by application control. The applications are accessed over HTTPS. What is the most likely missing configuration?

A.Web filter profile is not applied to the firewall policy.
B.SSL inspection is not configured and applied to the firewall policy.
C.Deep packet inspection is not enabled on the firewall policy.
D.IPS is not enabled on the firewall policy.
AnswerB

Application control must inspect the contents of an HTTP conversation to identify the application; but when the session is HTTPS, the payload is encrypted and opaque to the security engine. Without an SSL/SSH inspection profile applied to the firewall policy, FortiGate sees only the TLS handshake and the SNI field, so the protocol decoders cannot match application signatures. Enabling SSL inspection decrypts the HTTPS stream and makes the full payload available to application control. Therefore, the correct fix is to add and apply an SSL inspection profile on the same firewall policy that carries the application control profile.

Why this answer

Application control relies on inspecting the content of traffic to identify applications. When traffic is encrypted with HTTPS, the firewall cannot inspect the payload without decrypting it first. Therefore, SSL inspection must be configured and applied to the firewall policy to allow the FortiGate to decrypt the traffic and match it against application control signatures.

Exam trap

The trap here is that candidates confuse 'deep packet inspection' with 'SSL inspection,' but DPI is a broader concept that includes many inspection types, and the specific missing piece for HTTPS application identification is SSL inspection, not DPI as a whole.

How to eliminate wrong answers

Option A is wrong because a web filter profile controls access to URLs and categories, not the identification of applications; application control is a separate feature. Option C is wrong because deep packet inspection (DPI) is a general term that includes SSL inspection, but the specific missing configuration for encrypted traffic is SSL inspection, not DPI in general. Option D is wrong because IPS is an intrusion prevention system that detects and blocks threats, not a mechanism for identifying applications; it does not decrypt HTTPS traffic.

31
Multi-Selectmedium

A security administrator wants to ensure that all DNS queries from internal users are filtered to block access to known malicious domains. Which TWO configurations must be applied?

Select 2 answers
A.Enable deep inspection on the firewall policy
B.Apply the DNS Filter profile to the firewall policy that allows DNS traffic
C.Enable DNS inspection on the SSL/SSH inspection profile
D.Create a DNS Filter profile to block malicious domains
E.Configure a DNS server on the FortiGate
AnswersB, D

A DNS filter profile is a set of blocking rules and categories, but it is inert until it is attached to a firewall policy. When the policy matches DNS traffic, FortiGate applies the profile's rules — such as blocking malicious domains — and returns a 'blocked' response to the client. This is the enforcement point that makes DNS filtering actually work for traffic traversing the FortiGate.

Why this answer

Option B is correct because the DNS Filter profile only takes effect when it is attached to the firewall policy that permits the DNS traffic, so applying it to that policy is what actually enforces filtering on users' queries. Option D is correct because the DNS Filter profile itself is the object that defines which domains are blocked (e.g., via FortiGuard category-based filtering or static domain lists), so it must be created before it can be applied. Option A is not required because deep inspection applies to content/AV scanning of traffic, not to DNS query filtering.

Option C is incorrect because DNS inspection is not enabled through the SSL/SSH inspection profile; DNS filtering is handled by the DNS Filter profile. Option E is not needed because configuring a DNS server on the FortiGate does not filter or block malicious domains for internal users.

Exam trap

NSE4 often tests that DNS filtering requires both a profile and policy application, and candidates may mistakenly think deep inspection or SSL inspection is needed for DNS.

32
MCQmedium

A FortiGate is configured with an IPS profile to protect a web server. The administrator notices that some attacks are not being detected. The IPS signature database is up to date. What should the administrator check first?

A.Increase the severity level of the IPS sensor.
B.Ensure the IPS profile is applied to the firewall policy that handles traffic to the web server.
C.Disable flow-based inspection and enable proxy-based inspection.
D.Change the IPS signature action from 'default' to 'block'.
AnswerB

To protect a web server, the IPS profile must be attached to the firewall policy that controls access to that server, and that policy must actually match the traffic's source, destination, port, and interface. Without this attachment, the FortiGate forwards traffic based on the policy's action alone and never passes the packets to the IPS engine for inspection. Verify that the policy order places this rule before any catch-all policy, and confirm that the 'Security Profiles' section lists the desired IPS sensor; otherwise, the sensor is effectively dormant.

Why this answer

The most common reason an IPS profile fails to detect attacks is that the profile is not actually applied to the firewall policy processing the traffic. In FortiGate, an IPS sensor must be referenced in the security profile settings of the specific firewall policy that permits traffic to the web server. Without this binding, the IPS engine never inspects the packets, regardless of signature database freshness or sensor configuration.

Therefore, verifying policy association is the first and most fundamental troubleshooting step.

Exam trap

NSE4 often tests the misconception that IPS detection depends solely on signature database updates or sensor configuration, while overlooking the critical step of applying the IPS profile to the correct firewall policy.

How to eliminate wrong answers

Option A is wrong because increasing the severity level in the IPS sensor only changes which signatures are active based on severity; if the sensor is not applied to the policy, no signatures are evaluated at all. Option C is wrong because flow-based inspection is the default and fully supports IPS; switching to proxy-based inspection is not required for IPS detection and may introduce other issues. Option D is wrong because changing the action from 'default' to 'block' only affects whether a detected attack is blocked or allowed; it does not enable detection itself, and if the profile is not applied, no action occurs.

33
MCQmedium

A FortiGate administrator has configured a firewall policy with SSL deep inspection using a forward trust CA certificate. When users access an HTTPS website with a valid certificate, they still receive a certificate warning. What is the MOST likely reason?

A.The website certificate is expired
B.The forward trust CA certificate is not installed on the users' devices
C.The firewall policy is set to certificate inspection instead of deep inspection
D.The FortiGate's CA certificate is not trusted by the browser
AnswerB

SSL deep inspection re-signs each server certificate with the FortiGate's forward trust CA. Browsers only accept that forged certificate if the CA is trusted locally, so without the certificate installed in each device's trust store, every HTTPS site triggers a warning.

Why this answer

When SSL deep inspection is configured, the FortiGate generates a new certificate for each HTTPS session, signed by the forward trust CA. If the forward trust CA certificate is not installed in the trusted root store on the users' devices, the browser will not trust the generated certificate and will display a certificate warning. This is the most common cause of such warnings even when the original website certificate is valid.

Exam trap

The trap here is that candidates often confuse certificate inspection with deep inspection, or assume the FortiGate's own certificate is automatically trusted by clients, when in fact the forward trust CA must be explicitly deployed to all user devices.

How to eliminate wrong answers

Option A is wrong because if the website certificate were expired, the warning would be about an expired certificate, not a generic untrusted warning, and the question states the website has a valid certificate. Option C is wrong because certificate inspection does not re-sign certificates; it only checks the CN or SNI, so it would not cause a certificate warning from the browser. Option D is wrong because the FortiGate's CA certificate is the forward trust CA; if it were not trusted by the browser, that is exactly what option B describes — the CA certificate not being installed on the users' devices.

34
Multi-Selectmedium

An administrator configures a DLP profile to detect Social Security numbers in outbound traffic. The profile is applied to an outbound HTTP policy. Which TWO additional configurations are necessary for the DLP to inspect HTTPS traffic?

Select 2 answers
A.Set the firewall policy inspection mode to proxy-based
B.Add an SSL exemption for the destination servers
C.Enable SSL/TLS deep inspection on the firewall policy
D.Create a DLP sensor with the correct pattern and apply it to the policy
E.Configure a web filter profile to allow the traffic
AnswersC, D

SSL/TLS deep inspection is mandatory for DLP to detect sensitive data in HTTPS traffic. When enabled, FortiGate terminates the TLS session using its certificate as a trusted CA, decrypts the payload, and hands the plaintext to security profiles—including the DLP sensor—for inspection. Without deep inspection, only non-encrypted traffic or traffic subject to certificate inspection (which examines only certificate metadata) can be evaluated, making DLP blind to the content of an encrypted web session.

Why this answer

DLP inspection of HTTPS traffic requires the firewall to decrypt the encrypted payload. Enabling SSL/TLS deep inspection on the firewall policy allows FortiGate to perform man-in-the-middle decryption, re-encrypt, and then inspect the decrypted content for sensitive data like Social Security numbers. Without deep inspection, the DLP engine sees only encrypted traffic and cannot match patterns.

Exam trap

The trap here is that candidates often confuse SSL exemptions (which bypass inspection) with SSL deep inspection (which enables inspection), or assume that proxy-based mode alone is sufficient for HTTPS DLP, ignoring the mandatory decryption step.

35
MCQhard

An admin runs the following command on a FortiGate: 'diagnose sys session filter dport 443' and sees output: 'proto=6 proto_state=01 duration=3600 expire=3599'. What does this indicate?

A.The session is stuck in a half-open state due to a firewall policy misconfiguration
B.The session is in the SYN_SENT state and is not yet fully established
C.The session is fully established and has been active for 3600 seconds
D.The session is using UDP protocol
AnswerB

In FortiGate session output, proto_state=01 maps to TCP SYN_SENT in the TCP state machine. This means the session originated with a SYN packet and is currently awaiting a SYN-ACK from the server; the three-way handshake has not yet completed. Therefore, the session is not fully established and should not be treated as an active, fully formed session. This is the correct interpretation of the diagnostic data.

Why this answer

The output shows 'proto=6' (TCP), 'proto_state=01', 'duration=3600', and 'expire=3599'. In FortiGate's session table, proto_state=01 for TCP indicates the SYN_SENT state, meaning the session has sent a SYN but has not yet received the SYN-ACK. This confirms the session is not fully established.

Option B correctly identifies this as a half-open session in the SYN_SENT state.

Exam trap

The trap here is that candidates often assume 'duration=3600' means the session has been active for an hour and thus must be established, but the proto_state field (01) overrides that assumption by indicating the session is still in the SYN_SENT phase of the TCP handshake.

How to eliminate wrong answers

Option A is wrong because a half-open state due to firewall policy misconfiguration would typically show a different state or no session at all; the session is present but in SYN_SENT, which is a normal TCP handshake phase, not a misconfiguration. Option C is wrong because a fully established TCP session would show proto_state=02 (ESTABLISHED), not 01, and the duration/expire values do not indicate establishment status. Option D is wrong because proto=6 explicitly indicates TCP, not UDP (which would be proto=17).

36
Multi-Selectmedium

An administrator needs to block users from uploading files containing credit card numbers to external websites. Which TWO actions must be configured? (Choose two.)

Select 2 answers
A.Apply an antivirus profile to the policy
B.Enable SSL deep inspection on the firewall policy
C.Create a DLP profile with a credit card number sensor set to block
D.Configure application control to block file transfer applications
E.Use a web filter to block all upload websites
AnswersB, C

Enabling SSL deep inspection on the firewall policy is a prerequisite for any content-aware inspection of HTTPS traffic. It forces the firewall to decrypt outbound SSL/TLS sessions so that security profiles, including DLP, can examine the actual file contents being uploaded. By itself it does not block uploads; rather, it provides the visibility needed for a DLP sensor to detect and enforce a block on credit card data. This step is essential because without decryption, the firewall would merely see encrypted bytes and cannot apply data-loss prevention rules.

Why this answer

SSL deep inspection is required to decrypt HTTPS traffic so the firewall can inspect the content of encrypted uploads for sensitive data like credit card numbers. Without decryption, the DLP profile cannot see the payload of encrypted sessions, rendering the DLP sensor ineffective.

Exam trap

The trap here is that candidates often forget that DLP requires SSL inspection to see the content of encrypted traffic, and mistakenly think a DLP profile alone is sufficient to block credit card numbers in HTTPS uploads.

37
Multi-Selectmedium

Which TWO actions can cause SSL inspection to fail with certificate errors on client browsers? (Choose two.)

Select 2 answers
A.The FortiGate's CA certificate has expired.
B.The firewall policy allows the traffic.
C.The web server's certificate is signed by a public CA.
D.The client browser has the FortiGate CA certificate installed.
E.The FortiGate's generated server certificate does not match the requested domain name.
AnswersA, E

When the FortiGate's internal CA certificate is past its validity period, the FortiGate can no longer sign or re-sign the server certificates it presents to clients. Even if the generated leaf certificate has a future validity window, the browser will validate the entire chain and immediately flag the root/intermediate CA as expired, breaking trust and causing an 'untrusted authority' error during SSL inspection.

Why this answer

The FortiGate acts as a certificate authority (CA) for SSL inspection. If the FortiGate's CA certificate has expired, any server certificate it generates and signs for intercepted HTTPS sessions will be considered invalid by client browsers. Browsers will display a certificate error because the signing CA (the FortiGate) is no longer trusted due to expiration, even if the client has the CA certificate installed.

Exam trap

The trap here is that candidates often assume a public CA-signed server certificate is always trusted during inspection, forgetting that the FortiGate re-signs the certificate with its own CA, so the browser only sees the FortiGate's CA certificate and the generated server certificate, not the original public CA certificate.

38
MCQmedium

After enabling SSL inspection, a user receives a warning 'The certificate is not trusted' in the browser. The administrator has installed the CA certificate on the client. What else could be the cause?

A.The firewall policy denies the traffic.
B.The CA certificate is not added to the browser's trusted root store.
C.The FortiGate is not decrypting the traffic.
D.The web server's certificate has expired.
AnswerB

When SSL inspection is enabled on the FortiGate, it terminates the client's TLS connection and re-signs a new certificate for the requested website using its own local Certificate Authority. The browser will only trust this dynamically generated certificate if the FortiGate's CA certificate has been installed in the client's trusted root certificate store. If that CA is missing or untrusted, the browser warns that the certificate was not issued by a trusted authority, which is exactly the warning the user sees — this is the correct cause of the issue.

Why this answer

Even though the administrator installed the CA certificate on the client, the browser uses its own trusted root store, which is separate from the operating system's certificate store. If the CA certificate is not specifically added to the browser's trusted root store (e.g., Chrome uses the system store but Firefox maintains its own), the browser will still flag the certificate as untrusted. This is a common misconfiguration when deploying SSL inspection with FortiGate.

Exam trap

The trap here is that candidates assume installing the CA certificate on the client OS is sufficient for all browsers, but browsers like Firefox maintain their own certificate trust store, and even Chrome on some platforms may require the certificate to be in the correct store (e.g., the 'Trusted Root Certification Authorities' store) for the warning to disappear.

How to eliminate wrong answers

Option A is wrong because a firewall policy denying traffic would block the connection entirely, not generate a certificate trust warning in the browser. Option C is wrong because if FortiGate were not decrypting the traffic, the browser would receive the original web server certificate, which would be trusted (assuming it is a valid public CA), so no untrusted warning would appear. Option D is wrong because an expired web server certificate would cause a different error (e.g., 'expired certificate'), not specifically 'The certificate is not trusted' — and the FortiGate's re-signed certificate would be the one presented to the client, not the original server certificate.

39
MCQhard

An administrator configured SSL inspection with 'deep-inspection' profile. Users report that some websites fail to load with certificate errors. The firewall policy is correct. What is the most likely reason?

A.The CA certificate has expired.
B.The web server uses a cipher that the FortiGate cannot re-encrypt.
C.The user's browser is outdated.
D.The firewall needs a policy to allow DNS traffic.
AnswerB

When a FortiGate performs deep inspection, it terminates the client's TLS connection and then initiates a second TLS connection to the web server to re-encrypt traffic. If the web server negotiates a cipher suite, key exchange method, or TLS version that the FortiGate's SSL engine does not support or is not configured to allow, the outbound handshake fails. This manifests as a 'Cannot communicate securely' or certificate-related error for that specific server, while other sites that use supported ciphers continue to work. The administrator should review the SSL inspection profile's cipher list and ensure it aligns with the server's capabilities.

Why this answer

When deep-inspection is used, the FortiGate decrypts the client-to-server traffic, inspects the content, and then re-encrypts it before forwarding to the client. If the web server uses a cipher suite that the FortiGate does not support for re-encryption (e.g., an obsolete or non-standard cipher), the FortiGate cannot complete the SSL handshake with the client, causing certificate errors or connection failures. This is the most likely reason because the firewall policy is correct and the CA certificate is valid.

Exam trap

The trap here is that candidates often assume certificate errors are always due to an expired CA certificate, but the question specifies that only some websites fail, which points to a cipher mismatch during re-encryption rather than a global CA issue.

How to eliminate wrong answers

Option A is wrong because if the CA certificate had expired, the FortiGate would not be able to generate valid signed certificates for any inspected site, causing all deep-inspection sessions to fail, not just some websites. Option C is wrong because an outdated browser might cause compatibility issues with modern ciphers, but the error described is a certificate error specifically from the FortiGate's re-encryption process, not a browser-side cipher mismatch. Option D is wrong because DNS traffic is typically allowed by default in the implicit allow policy or a separate DNS policy; a missing DNS policy would prevent name resolution entirely, not cause certificate errors on specific websites.

40
MCQmedium

A company uses deep SSL inspection to filter traffic. Users report that some HTTPS sites are not loading. The administrator checks the FortiGate and sees that the certificate for the sites is not trusted on the client machines. What is the most likely cause?

A.The FortiGate's CA certificate is not installed in the Trusted Root Certification Authorities store on the clients.
B.The FortiGate is using a self-signed certificate for the SSL inspection policy.
C.The SSL inspection policy is set to 'no-inspection' for the affected sites.
D.The FortiGate's web filter profile is blocking the certificate.
AnswerA

The FortiGate's CA certificate is not installed in the Trusted Root Certification Authorities store on the clients. Deep SSL inspection works by having the FortiGate intercept TLS traffic and present a real-time generated certificate signed by a FortiGate-owned CA. If that CA is not present in the client's trusted root store, the browser cannot verify the chain of trust and will display a certificate error or block the connection entirely. Installing the FortiGate CA in the Trusted Root Certification Authorities store on all clients is a mandatory prerequisite for seamless deep inspection.

Why this answer

When deep SSL inspection is enabled, the FortiGate acts as a man-in-the-middle by decrypting HTTPS traffic using a local CA certificate. For clients to trust the decrypted connections, the FortiGate's CA certificate must be installed in the Trusted Root Certification Authorities store on each client machine. If it is missing, the browser will display a certificate trust error and may block the site, causing the reported loading failures.

Exam trap

The trap here is that candidates may confuse the FortiGate's self-signed certificate used for its own web interface with the CA certificate required for deep inspection, or assume that 'no-inspection' would cause loading failures rather than bypassing inspection entirely.

How to eliminate wrong answers

Option A is correct because the root cause is the missing CA certificate on clients. Option B is wrong because a self-signed certificate in the SSL inspection policy is used for the FortiGate's own management interface or for certificate re-signing, but the core issue is the CA certificate not being trusted by clients, not the type of certificate used in the policy. Option C is wrong because setting the policy to 'no-inspection' would bypass SSL inspection entirely, allowing HTTPS sites to load normally without certificate errors.

Option D is wrong because a web filter profile blocks URLs or categories based on policy, not certificates; certificate trust is handled by the SSL inspection configuration, not the web filter.

41
MCQmedium

An administrator configures an antivirus profile in proxy-based inspection mode on a FortiGate. However, SMTP traffic is not being scanned for viruses. The firewall policy includes the antivirus profile and the FortiGate has a valid FortiGuard subscription. What is the most likely cause?

A.Flow-based inspection is required for SMTP scanning
B.The SMTP protocol is not enabled in the proxy options of the security profile
C.The FortiGate does not have a valid SSL certificate for SMTP inspection
D.The antivirus profile is configured to scan only HTTP traffic
AnswerB

In proxy-based inspection, each protocol must be explicitly enabled in the proxy options of the security profile. If SMTP is left unchecked, the FortiGate will not decode or scan SMTP traffic, causing the antivirus profile to appear non-functional for email. Navigate to the AV profile's protocol options and ensure SMTP is enabled, then apply the profile to the firewall policy that carries SMTP traffic.

Why this answer

In proxy-based inspection mode, the antivirus profile relies on the proxy options to determine which protocols to scan. If SMTP is not explicitly enabled in the proxy options of the security profile, the FortiGate will not inspect SMTP traffic for viruses, even if the antivirus profile is applied to the policy and the FortiGuard subscription is valid.

Exam trap

The trap here is that candidates assume a valid FortiGuard subscription and a correctly applied antivirus profile guarantee scanning of all traffic, overlooking the requirement to enable the specific protocol in the proxy options for proxy-based inspection.

How to eliminate wrong answers

Option A is wrong because flow-based inspection is not required for SMTP scanning; proxy-based inspection supports SMTP scanning when the protocol is enabled in the proxy options. Option C is wrong because SMTP traffic does not require SSL inspection for antivirus scanning; SSL certificates are only relevant for HTTPS or SMTPS inspection. Option D is wrong because antivirus profiles do not have a setting to scan only HTTP traffic; they scan all protocols enabled in the proxy options or flow-based configuration.

42
MCQeasy

A company wants to block all peer-to-peer file sharing applications on the network. Which FortiGate feature should be used to achieve this goal?

A.Application Control
B.Web Filter
C.DNS Filter
D.Intrusion Prevention System (IPS)
AnswerA

Application Control is the correct security feature because it uses deep packet inspection and application signatures to identify P2P traffic regardless of port or protocol. It can block specific applications like BitTorrent, eMule, or LimeWire by matching their unique traffic patterns, even when they use non-standard ports or encryption. This is the only option that directly governs application usage rather than relying on ancillary factors such as URLs or hostnames.

Why this answer

Application Control is the correct feature because it is specifically designed to identify and block peer-to-peer (P2P) file-sharing applications by inspecting traffic patterns and signatures, regardless of the port or protocol used. Unlike port-based blocking, Application Control uses deep packet inspection (DPI) to recognize P2P protocols such as BitTorrent, eDonkey, and Gnutella, even when they attempt to evade detection by using non-standard ports or encryption.

Exam trap

The trap here is that candidates often confuse Application Control with IPS, assuming that IPS can block any unwanted traffic, but IPS focuses on threats and exploits, not on enforcing acceptable use policies for specific applications like P2P file sharing.

How to eliminate wrong answers

Option B (Web Filter) is wrong because it controls access to URLs and web content categories, not the application-layer protocols used by P2P file-sharing software. Option C (DNS Filter) is wrong because it blocks or redirects DNS queries to specific domains, but P2P applications often use hardcoded IP addresses or peer discovery mechanisms that bypass DNS entirely. Option D (Intrusion Prevention System) is wrong because IPS is designed to detect and block network-based attacks and vulnerabilities, not to enforce application usage policies like blocking P2P file sharing.

43
MCQmedium

A FortiGate is configured to integrate with FortiSandbox for advanced threat detection. The antivirus profile is set to send files to FortiSandbox when a virus is detected. What action does FortiGate take on the file while it is being analyzed by FortiSandbox?

A.Quarantines the file on the FortiGate
B.Blocks the file until a verdict is received from FortiSandbox
C.Immediately blocks the file and logs the event
D.Allows the file to pass through and logs the event
AnswerB

When the FortiGate is integrated with FortiSandbox, the administrator can configure the sandbox profile to 'block' while the file is being analyzed, meaning the FortiGate holds or buffers the file and does not deliver it to the client until a verdict is received from FortiSandbox. This approach ensures that unknown files are not released to the endpoint unless the sandbox deems them clean, with a fallback action applied if the verdict times out. This is the correct behavior for a blocking integration, as it prevents potential malware from reaching the user during the analysis window.

Why this answer

When the antivirus profile is configured to send files to FortiSandbox for analysis, FortiGate holds the file in a temporary buffer and does not forward it to the client until a verdict is received. This is known as 'block until verdict' mode. The file is not quarantined on the FortiGate, nor is it immediately blocked or allowed; the session is paused pending the sandbox result.

Exam trap

NSE4 often tests the difference between 'block until verdict' and 'quarantine' actions in antivirus profiles, confusing candidates about whether the file is held or stored.

How to eliminate wrong answers

Option A is wrong because quarantine on FortiGate is a separate action used for infected files that are stored for further inspection, not for files awaiting sandbox analysis. Option C is wrong because immediate blocking occurs only if a virus is already detected by the local AV engine, not when the file is sent to FortiSandbox for analysis. Option D is wrong because allowing the file to pass through would defeat the purpose of sandboxing; FortiGate does not permit the file until a verdict is received.

44
Multi-Selecthard

An administrator receives reports that some internal users can access Facebook despite a web filtering profile that blocks the 'Social Networking' category. The policy is configured with deep inspection. Which THREE checks should the administrator perform to troubleshoot this issue?

Select 3 answers
A.Check if the users are using HTTPS and if the SSL inspection profile has an exemption for Facebook
B.Ensure that the antivirus profile is enabled on the policy
C.Check if the users are accessing Facebook via an SSL VPN tunnel that bypasses the policy
D.Verify that the web filtering profile is applied to the correct policy and that the policy order is correct
E.Confirm that the 'Social Networking' category is not set to 'Monitor' instead of 'Block'
AnswersA, C, D

When users connect to Facebook over HTTPS, FortiGate must decrypt the TLS session (or at least inspect the Server Name Indication) to determine the destination domain and apply URL category filtering. If the SSL inspection profile configured on the policy includes a certificate exemption for Facebook (often added to avoid certificate pinning errors or breakage), the firewall skips decryption entirely and cannot see the SNI or the full URL. As a result, the web filter is effectively blind to the HTTPS session, and the Social Networking category is never matched, allowing the traffic even though the profile is set to Block.

Why this answer

The troubleshooting should focus on three main areas: (A) SSL inspection exemption – if users access Facebook via HTTPS and the SSL inspection profile exempts Facebook traffic, it bypasses the web filter; (C) SSL VPN bypass – traffic through an SSL VPN tunnel may not match the policy if the tunnel interface is not covered; (D) policy application and order – the web filtering profile must be applied to the correct policy and the policy order must be such that this policy is enforced before any conflicting policy. Option E is a valid check, but since the category is already set to 'Block' in the profile, the issue is more likely related to the other three.

Exam trap

A common pitfall is assuming that simply applying a web filtering profile with a block action is sufficient, overlooking SSL inspection exemptions, VPN bypasses, or policy misapplication. The three key checks are verifying SSL inspection exemptions (A), ensuring traffic isn't bypassing via SSL VPN (C), and confirming the correct policy and order (D). Checking the category action (E) is secondary because the profile is already set to block.

45
MCQmedium

A FortiGate with antivirus in flow-based inspection mode is not detecting a known virus in HTTP traffic. The same virus is detected when using proxy-based inspection. What is the most likely reason?

A.Flow-based inspection does not reassemble files or unpack archives, so it misses some viruses
B.Flow-based inspection requires FortiSandbox integration to detect viruses
C.The antivirus signature database is outdated for flow-based inspection
D.Flow-based inspection only scans on explicit proxy policies
AnswerA

In flow-based inspection, FortiOS scans traffic in a single pass by inspecting packets as they traverse the interface without buffering the entire file. Because it does not reassemble the full content or unpack compressed archives (e.g., ZIP, RAR, or base64-encoded files), malware hidden inside these containers can evade detection. Proxy-based inspection, in contrast, buffers the whole object, unpacks archives, and scans each component individually, offering deeper and more thorough virus detection than flow mode.

Why this answer

Flow-based inspection processes traffic as a stream without performing full file reassembly or unpacking archives that proxy-based inspection performs. This allows some viruses to evade detection.

46
MCQhard

A security administrator is configuring an IPS sensor on a FortiGate to protect a web server. The sensor includes a signature that detects a specific HTTP exploit. The administrator wants to ensure that the signature blocks the attack but also generates a log entry for each detection. Which action should be taken for that signature in the IPS sensor?

A.Set the action to 'Reset' and enable 'Logging'.
B.Set the action to 'Monitor' and enable 'Packet Logging'.
C.Set the action to 'Block' and enable 'Logging' for the signature.
D.Set the action to 'Block' and enable 'Packet Logging'.
AnswerC

In a FortiGate IPS sensor, each signature can be configured with an action and logging. Setting the action to 'Block' drops the matching traffic, and enabling logging ensures an event is recorded. This directly meets the requirement to block the attack and generate a log entry for each detection.

Why this answer

In a FortiGate IPS sensor, the 'Block' action drops packets matching the signature, preventing the exploit from reaching the server. Enabling 'Logging' for that signature ensures an event is recorded each time the signature is triggered. This combination satisfies both the blocking and logging requirements without unnecessary packet capture or connection resets.

Exam trap

The trap here is confusing 'Packet Logging' with standard event logging; packet logging captures raw packets for deep analysis, while standard logging records the event details.

47
MCQeasy

A company wants to block all HTTP traffic but allow HTTPS. Which SSL inspection method should be used on the firewall policy?

A.No inspection
B.Deep inspection
C.Full SSL inspection
D.Certificate inspection
AnswerA

Applying no SSL inspection to the policy means the FortiGate does not decrypt or examine HTTPS traffic; it simply passes it through based on the destination port (443). This is the appropriate and efficient choice when the requirement is to block HTTP (port 80) while allowing HTTPS, because the firewall can enforce that distinction entirely through policy rules without the overhead or privacy implications of encryption decryption.

Why this answer

To block HTTP (port 80) while allowing HTTPS (port 443), no SSL inspection is needed because the firewall can distinguish traffic by port number alone. SSL inspection is only required when you need to examine the encrypted payload of HTTPS traffic, not to permit or deny it based on the protocol. Therefore, 'No inspection' is correct for this access control requirement.

Exam trap

The trap here is that candidates assume HTTPS traffic must be inspected to be allowed, but the firewall can permit or deny based on the destination port without any SSL inspection at all.

How to eliminate wrong answers

Option B (Deep inspection) is wrong because deep inspection decrypts HTTPS traffic to inspect the payload, which is unnecessary and adds overhead when the goal is simply to allow HTTPS and block HTTP based on port. Option C (Full SSL inspection) is wrong because it also involves decrypting all SSL/TLS traffic, which is not required for port-based allow/deny decisions. Option D (Certificate inspection) is wrong because certificate inspection only validates the server certificate without decrypting the traffic, but it is still an SSL inspection method that is not needed for simple port-based filtering.

48
MCQhard

A FortiGate administrator runs the following command and sees: 'diagnose ips anomaly list' returns no entries, but the IPS sensor is configured with anomaly signatures. What is the MOST likely reason the signatures are not appearing?

A.The IPS sensor is configured in 'passive' mode, which suppresses anomaly detection.
B.The anomaly signatures have not triggered any events yet because traffic thresholds have not been exceeded.
C.Anomaly signatures are not displayed by 'diagnose ips anomaly list'; they require a different command.
D.The IPS sensor is not enabled on any firewall policy.
AnswerB

Anomaly signatures in FortiOS are rate-based detectors that only generate an event when traffic exceeds a configured threshold, such as packets per second or concurrent connections. The command output lists only triggered anomalies, not configured ones. If no traffic has exceeded the threshold, the list remains completely empty, which is a normal operational state.

Why this answer

The 'diagnose ips anomaly list' command displays only anomaly signatures that have been triggered and are currently in a state where thresholds have been exceeded. If no entries appear, it means the configured anomaly signatures have not yet detected traffic surpassing their defined thresholds (e.g., packets per second, connections per second). Anomaly signatures are threshold-based and only become active when the monitored traffic exceeds the configured limits, at which point they would appear in the list.

Exam trap

The trap here is that candidates assume 'diagnose ips anomaly list' shows all configured anomaly signatures, but it only shows those that have been triggered by exceeding thresholds, leading them to incorrectly suspect a configuration or policy issue.

How to eliminate wrong answers

Option A is wrong because IPS sensors do not have a 'passive' mode that suppresses anomaly detection; passive mode in FortiGate refers to the IPS engine's action (e.g., monitoring without blocking), but anomaly signatures still trigger and appear in the list if thresholds are exceeded. Option C is wrong because 'diagnose ips anomaly list' is the correct command to display triggered anomaly signatures; no alternative command is needed for this purpose. Option D is wrong because even if the IPS sensor is not enabled on any firewall policy, the anomaly signatures would still be configured in the sensor and would appear in the 'diagnose ips anomaly list' output if they had triggered, though they would not affect traffic; the absence of entries is due to thresholds not being exceeded, not policy attachment.

49
Multi-Selecthard

A FortiGate administrator notices that some users can bypass the web filter to access prohibited categories. The web filter profile is applied to the firewall policy. Which TWO actions should the admin take to determine why the filter is being bypassed? (Choose two.)

Select 2 answers
A.Ensure that the FortiGate has connectivity to FortiGuard
B.Check if the firewall policy that the traffic matches has the web filter profile applied
C.Verify that the DNS filter is also applied to the same policy
D.Check if SSL deep inspection is enabled on the policy
E.Examine the client's browser proxy settings
AnswersB, D

In FortiOS, web filtering is enforced only when a web filter profile is explicitly attached to the firewall policy that matches the traffic. If the policy used by the affected users does not have the profile selected, the FortiGate will not inspect URLs and will allow all web traffic, creating a bypass. The administrator should examine the policy's Security Profiles section to confirm the web filter profile is applied. This is the most direct and common cause of a partial web filter bypass.

Why this answer

Option B is correct because if the firewall policy that actually matches the user's traffic does not have the web filter profile attached, the filter is never evaluated and users can reach prohibited categories; the admin must confirm the profile is applied on the matching policy, not just on some other policy. Option D is correct because without SSL deep inspection the FortiGate cannot decrypt HTTPS traffic, so it cannot inspect the URL path or content and the web filter is effectively bypassed for HTTPS sites. Option A is not the primary troubleshooting step here since FortiGuard connectivity issues would typically cause rating failures or blocks rather than selective bypass, and the question focuses on why filtering is bypassed.

Option C is incorrect because the DNS filter is a separate feature and its absence does not explain why the web filter profile is not blocking traffic. Option E is incorrect because client browser proxy settings are not a FortiGate web filter configuration element and would not be the standard cause of the filter being bypassed in this scenario.

Exam trap

NSE4 often tests the misconception that attaching a web filter profile is sufficient, ignoring that policy match order and SSL deep inspection are required for the filter to actually see and block HTTPS traffic.

50
MCQmedium

A company is deploying FortiGate for outbound web filtering. They want to block users from accessing social media sites during business hours, but still allow access to cloud-based productivity tools like Office 365. Which approach should the administrator use to meet this requirement?

A.Create a firewall policy to block all traffic to ports commonly used by social media (e.g., TCP 443).
B.Use a web filter profile to block URLs containing 'facebook' or 'twitter'.
C.Configure an application control profile with rules to block social media applications and allow Office 365 applications.
D.Implement a DNS filter to block DNS queries for social media domains.
AnswerC

Application control is the correct approach because it classifies traffic based on application signatures and behaviors rather than static port numbers or URL strings. A properly configured application control profile can identify and block specific social media applications—even when they run over HTTPS or use non-standard ports—while explicitly allowing Office 365 applications, including Outlook, Teams, and SharePoint Online. This granularity meets the exact requirement without disrupting business-critical services, and with SSL inspection enabled, it remains effective against encrypted social media traffic.

Why this answer

Application control is the correct approach because it can identify and control applications like social media and Office 365 based on their unique signatures, regardless of the ports or protocols they use. Unlike URL filtering or port blocking, application control can differentiate between Office 365 traffic and social media traffic even when both use HTTPS on TCP 443, allowing the administrator to block social media while permitting cloud productivity tools.

Exam trap

The trap here is that candidates often assume URL filtering or port blocking is sufficient, but the NSE4 exam tests the understanding that application control is required when applications share the same port (e.g., TCP 443) and need to be differentiated based on their behavior, not just their domain or port.

How to eliminate wrong answers

Option A is wrong because blocking TCP 443 would block all HTTPS traffic, including Office 365 and other legitimate web services, not just social media. Option B is wrong because URL filtering based on keywords like 'facebook' or 'twitter' is unreliable—social media sites often use dynamic URLs, CDNs, or IP addresses that do not contain those keywords, and users can bypass it via direct IP access or HTTPS encryption. Option D is wrong because DNS filtering only blocks domain resolution; users could still access social media by using direct IP addresses, cached DNS entries, or alternative DNS servers, making it an incomplete solution.

51
Multi-Selecthard

An administrator is configuring an IPS sensor to protect a web server. The administrator wants to ensure that the IPS blocks attacks targeting the web server, but also wants to minimize false positives. Which two actions should the administrator take when configuring the IPS sensor? (Choose two.)

Select 2 answers
A.Enable IPS signature updates and use the 'recommended' action for signatures.
B.Set the action for all signatures to 'monitor' to avoid false positives.
C.Set the action for critical and high severity signatures to 'block'.
D.Apply the IPS sensor only to the firewall policy that allows traffic to the web server.
E.Enable all signatures and set the action to 'block' for all.
AnswersC, D

Setting critical and high severity signatures to block ensures that the most dangerous attacks are stopped. These signatures are typically well-tested and have low false positive rates. This balances security with minimizing false positives, as lower severity signatures might be more prone to false positives.

Why this answer

To block attacks while minimizing false positives, the administrator should focus on high-severity signatures with block action and apply the IPS sensor only to the relevant traffic. This targeted approach ensures critical threats are stopped without disrupting legitimate traffic. Other options either block everything (causing false positives) or monitor everything (not blocking).

Exam trap

The trap here is thinking that enabling all signatures with block action is the most secure, but it often leads to false positives and network disruption.

52
MCQeasy

Which web filtering feature allows an administrator to force web search engines to filter explicit content in search results, regardless of the user's browser settings?

A.DNS filter
B.URL filter
C.Application control
D.Safe search
AnswerD

Safe search enforcement rewrites search-engine traffic so the engine itself filters explicit results, independent of browser preferences. This satisfies the requirement to force filtering regardless of user browser settings, since the FortiGate modifies the request rather than relying on client-side configuration.

Why this answer

Safe search is a web filtering feature that forces supported search engines (e.g., Google, Bing, Yahoo) to filter explicit content from search results by appending specific query parameters (such as `safe=active` for Google) to the search request. This enforcement occurs at the FortiGate proxy level, overriding the user's browser settings and ensuring compliance with acceptable use policies.

Exam trap

The trap here is that candidates often confuse DNS filter or URL filter with safe search, thinking that blocking explicit content at the domain or URL level is equivalent to filtering search results, but only safe search modifies the actual search engine query parameters to enforce content filtering at the source.

How to eliminate wrong answers

Option A is wrong because DNS filter controls access based on domain name resolution (e.g., blocking or redirecting DNS queries to known malicious or category-based domains), but it does not modify search engine query parameters to enforce content filtering. Option B is wrong because URL filter blocks or allows access based on the full URL path or pattern (e.g., blocking specific URLs or categories), but it cannot inject parameters into search engine requests to enforce safe search. Option C is wrong because application control identifies and controls application traffic (e.g., blocking or shaping social media or streaming apps), but it does not have the capability to modify HTTP request parameters within search engine queries.

53
MCQeasy

Which SSL/TLS inspection mode only validates the server certificate without decrypting the traffic?

A.Deep inspection
B.Flow-based inspection
C.Certificate inspection
D.Proxy-based inspection
AnswerC

Certificate inspection is correct because this SSL/TLS inspection mode only validates the server certificate and does not perform any decryption of the encrypted session. FortiGate forwards the client hello, receives the server certificate, and verifies its validity (e.g., signing chain, issuer, trust, and possible revocation) while leaving the payload encrypted and untouched. This mode is lightweight, preserves performance, and is typically used when you only need to enforce certificate-based policies or ensure clients do not connect to untrusted servers. It does not inspect application content, making it the only mode that strictly only validates the server certificate.

Why this answer

Certificate inspection is the correct answer because it validates the server certificate's authenticity and expiration without decrypting the traffic. This mode checks the certificate chain and revocation status using OCSP or CRLs, but the encrypted payload remains untouched, preserving end-to-end encryption.

Exam trap

The trap here is that candidates confuse 'certificate inspection' with 'deep inspection' because both involve SSL/TLS, but deep inspection requires decryption while certificate inspection does not.

How to eliminate wrong answers

Option A is wrong because deep inspection performs full SSL/TLS decryption and re-encryption to inspect the application-layer content, not just certificate validation. Option B is wrong because flow-based inspection (also known as flow-based SSL inspection) decrypts traffic to analyze flows and signatures, not just certificates. Option D is wrong because proxy-based inspection establishes a man-in-the-middle proxy that decrypts and re-encrypts all traffic, requiring full certificate handling, not mere validation.

54
MCQeasy

Which security profile type is used to prevent sensitive data such as credit card numbers from being sent out of the network via email or web traffic?

A.Email filter profile
B.Antivirus profile
C.Web filter profile
D.DLP profile
AnswerD

A DLP (Data Leak Prevention) profile uses dictionaries of sensitive data types—such as credit card numbers, US Social Security numbers, dates of birth, and custom regex patterns—and inspects traffic content at the application layer to detect matches in files, HTTP posts, emails, or FTP transfers. When a match occurs, the DLP sensor can log, alert, quarantine, or block the transaction, and it can be applied in a FortiGate security policy together with antivirus and web-filter profiles. Its purpose is specifically to prevent or control the unauthorized transfer of sensitive data, making it the correct profile for this requirement.

Why this answer

A DLP (Data Loss Prevention) profile is specifically designed to inspect content in transit (e.g., email, web traffic) and block or alert on sensitive data patterns such as credit card numbers, Social Security numbers, or other regulated data. Unlike other security profiles, DLP uses predefined or custom data identifiers and pattern matching to enforce data protection policies, making it the correct choice for preventing sensitive data exfiltration.

Exam trap

The trap here is that candidates often confuse DLP with email filtering or web filtering, assuming that content inspection for sensitive data is handled by those profiles, but DLP is the only profile dedicated to data loss prevention with pattern-based content inspection.

How to eliminate wrong answers

Option A is wrong because an email filter profile focuses on spam, phishing, and malware detection in email traffic, not on scanning for sensitive data patterns like credit card numbers. Option B is wrong because an antivirus profile detects and blocks malicious files or malware signatures, but it does not inspect the content of data for sensitive information patterns. Option C is wrong because a web filter profile controls access to websites based on URL categories or reputation, not on the content of data being transmitted in HTTP/HTTPS requests or responses.

55
Multi-Selectmedium

A FortiGate administrator is troubleshooting why antivirus scanning is not working for HTTPS traffic. Which TWO steps should be verified?

Select 2 answers
A.Ensure the antivirus profile is set to proxy-based inspection
B.Ensure the firewall policy has SSL/TLS deep inspection enabled
C.Confirm that the web filter profile is also applied
D.Verify that the antivirus profile is applied to the policy
E.Check that the FortiSandbox is online for advanced scanning
AnswersB, D

Without SSL/TLS deep inspection enabled on the firewall policy, HTTPS sessions pass through still encrypted, and the antivirus engine can only see the outer TLS handshake, not the HTTP payload or files inside. Deep inspection forces the FortiGate to terminate the TLS connection, decrypt the content, scan it with the antivirus profile, then re-encrypt the session to the client. This is the most likely root cause when antivirus misses malware in HTTPS traffic, since the profile itself may be correctly configured but cannot see inside the tunnel.

Why this answer

HTTPS traffic is encrypted, so the FortiGate must decrypt it using SSL/TLS deep inspection before the antivirus engine can scan the payload. Without deep inspection, the antivirus profile sees only encrypted packets and cannot detect threats within the HTTPS stream.

Exam trap

The trap here is that candidates often assume proxy-based inspection is required for HTTPS antivirus scanning, but the critical step is enabling SSL/TLS deep inspection on the firewall policy, regardless of the inspection mode.

56
Matchingmedium

Match each FortiGate NAT type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Translates private source IP to public IP for outbound traffic

Translates public destination IP to private IP for inbound traffic

Assigns a range of ports to a private IP for NAT

Translates IPv6 traffic to IPv4 and vice versa

Translates IPv4 traffic to IPv6

Why these pairings

Source NAT modifies source IP of outgoing packets; Destination NAT modifies destination IP of incoming packets; Static NAT provides one-to-one mapping; PAT enables many-to-one translation via ports. Distractors swap the descriptions of Source and Destination NAT.

57
MCQeasy

A FortiGate administrator wants to block all traffic to websites that are categorized as 'Malware' and 'Phishing'. Which security profile should be configured to achieve this goal?

A.DNS Filter profile
B.Web Filter profile
C.IPS profile
D.Application Control profile
AnswerB

A Web Filter profile is the correct mechanism because it applies FortiGuard URL category classification directly to HTTP/HTTPS traffic in the firewall policy. By referencing categories such as Malware and Phishing, the profile can immediately block all sessions to sites in those categories, regardless of the actual IP address, and it supports exemptions and overrides. The profile also integrates with antivirus inspection and SSL deep inspection for encrypted traffic, providing a holistic web access control.

Why this answer

A Web Filter profile on FortiGate is used to block or allow traffic based on website categories, including 'Malware' and 'Phishing'. It leverages FortiGuard category-based filtering to inspect HTTP/HTTPS traffic and apply actions (block, allow, monitor) per category, making it the correct profile to block those specific website categories.

Exam trap

NSE4 often tests the distinction between Web Filter (URL categories) and DNS Filter (DNS-based blocking) — candidates may choose DNS Filter thinking it blocks malware sites, but it does not use the same category database.

How to eliminate wrong answers

Option A is wrong because DNS Filter profiles block based on DNS queries and are used for DNS-based filtering, not for categorizing and blocking website content by FortiGuard categories like Malware/Phishing. Option C is wrong because IPS profiles detect and block exploits and vulnerabilities, not website categories. Option D is wrong because Application Control profiles manage applications (e.g., Facebook, BitTorrent) based on application signatures, not website content categories.

58
MCQeasy

What is the purpose of the DNS filter security profile on a FortiGate?

A.To block DNS queries to known malicious domains
B.To inspect DNS traffic for virus signatures
C.To filter spam emails based on DNS blacklists
D.To prevent DNS tunneling attacks
AnswerA

The DNS filter profile inspects DNS queries and responses, blocking requests to known malicious domains using FortiGuard's domain threat intelligence. This satisfies the stem's requirement by preventing resolution before a connection occurs, stopping malware command-and-control and phishing at the DNS layer rather than at the subsequent HTTP session.

Why this answer

The DNS filter security profile on a FortiGate is designed to block DNS queries to known malicious domains by comparing the domain names in DNS requests against a regularly updated database of malicious or categorized domains. This prevents users from resolving domains associated with malware, phishing, or command-and-control servers, thereby stopping threats before an IP connection is even established.

Exam trap

The trap here is that candidates often confuse DNS filter with antivirus or antispam profiles, mistakenly thinking it inspects payloads or email content, when in fact it operates strictly at the DNS query layer to block domain resolution.

How to eliminate wrong answers

Option B is wrong because DNS filter does not inspect DNS traffic for virus signatures; that function is performed by antivirus profiles, which scan file attachments or payloads for malware patterns. Option C is wrong because filtering spam emails based on DNS blacklists is a feature of antispam profiles, not DNS filter — DNS filter operates at the DNS query level, not on email content. Option D is wrong while DNS tunneling is a real attack, the primary purpose of DNS filter is to block queries to malicious domains, not to detect or prevent DNS tunneling; tunneling detection requires deep packet inspection or anomaly-based analysis, typically handled by IPS or application control profiles.

59
MCQeasy

Which FortiGate security profile is BEST suited for blocking DNS queries to known malicious domains?

A.Web Filter profile
B.IPS profile
C.Application Control profile
D.DNS Filter profile
AnswerD

DNS Filter profile is purpose-built to inspect DNS query messages on port 53, comparing the queried domain against FortiGuard’s DNS category database and botnet indicators. It can take actions such as block, monitor, redirect, or allow based on domain category, and it supports sinkholing for botnet C2 domains. By operating below the web and application layers, DNS Filter can block malicious domains even for HTTPS, non-HTTP, or custom applications, making it the correct choice for DNS-level blocking.

Why this answer

The DNS Filter profile on FortiGate is purpose-built to inspect DNS queries and block resolution of known malicious domains by comparing them against FortiGuard DNS threat intelligence. It operates at the DNS layer, so it stops the connection before it is even established. This is the most direct and efficient control for blocking DNS queries to malicious domains.

Exam trap

NSE4 often tests the layer confusion between Web Filter (HTTP/HTTPS) and DNS Filter (DNS), so candidates pick Web Filter thinking it covers all domain-based blocking.

How to eliminate wrong answers

Option A is wrong because a Web Filter profile inspects HTTP/HTTPS requests and categories, not DNS queries, so it cannot block resolution of a malicious domain at the DNS layer. Option B is wrong because an IPS profile inspects packet payloads for exploit signatures and anomalies, not DNS domain reputation. Option C is wrong because Application Control identifies and controls applications by signature, not by DNS domain reputation.

60
Multi-Selecthard

An administrator needs to ensure that all HTTPS traffic to a critical server is inspected by the IPS. The server uses a valid certificate from a public CA. Which THREE steps are required to achieve this?

Select 3 answers
A.Apply an IPS profile to the same firewall policy
B.Set the Antivirus profile to 'Deep Inspection'
C.Install the FortiGate's CA certificate on client browsers
D.Enable SSL deep inspection on the firewall policy
E.Upload the server's certificate to the FortiGate
AnswersA, C, D

This is necessary because even with SSL deep inspection enabled, the decrypted traffic is only inspected if an IPS profile is attached to the policy. The IPS engine then examines the plaintext HTTP/HTTPS payloads for signatures, vulnerabilities, and exploits. Without an IPS profile, deep inspection alone just decrypts/encrypts but doesn't provide intrusion prevention.

Why this answer

Option D is correct because SSL deep inspection must be enabled on the firewall policy so the FortiGate decrypts the HTTPS session and can pass the plaintext to the IPS engine; without it, the IPS only sees encrypted traffic. Option A is correct because the IPS profile must be attached to that same firewall policy that carries the inspected traffic, otherwise the decrypted stream is never scanned by the IPS sensors. Option C is correct because deep inspection causes the FortiGate to re-sign the server's certificate with its own CA (the FortiGate's local/protection CA), so client browsers must trust that CA certificate to avoid certificate warnings and failed connections.

Option B is wrong because 'Deep Inspection' is a setting of the SSL/SSH inspection profile, not the Antivirus profile, and antivirus is not what performs IPS inspection. Option E is wrong because the server already presents a valid public CA certificate; the FortiGate does not need the server's certificate uploaded to perform deep inspection.

Exam trap

NSE4 often tests the misconception that uploading the server's certificate is required for deep inspection, when actually the FortiGate's CA certificate must be trusted by clients.

61
MCQmedium

A network administrator notices that some users can access blocked web categories despite a web filter profile applied to the policy. The admin runs 'diagnose debug rating' and sees 'rating not allow' for the category. What is the MOST likely cause?

A.The web filter profile has an 'override' configured for those users
B.The policy is not using the correct web filter profile
C.DNS filter is allowing the domain
D.The FortiGuard web filter database is outdated
AnswerA

A web filter override is an explicit exemption configured inside the FortiGate profile that lets certain users, groups, or source IPs bypass the FortiGuard rating decision. When an override is in place, the FortiGuard rating may still be evaluated as 'not allow' (blocked), but the override action overrides that result and permits the session. This exactly matches the symptom where only some users, presumably those included in the override rule, can access sites that are otherwise blocked for everyone else.

Why this answer

The 'rating not allow' message in the 'diagnose debug rating' output indicates that the FortiGate's rating engine correctly identified the category as blocked by the web filter profile. However, if an 'override' is configured for specific users or groups, it allows them to bypass the blocked category. This explains why some users can access the site despite the profile blocking it, as the override takes precedence over the profile's default action.

Exam trap

The trap here is that candidates often assume a 'rating not allow' message means the filter is working correctly for everyone, overlooking the possibility that an override configured within the same profile can selectively permit access for certain users.

How to eliminate wrong answers

Option B is wrong because if the policy were not using the correct web filter profile, the 'diagnose debug rating' output would not show 'rating not allow' for the category; it would either show no rating or a different profile reference. Option C is wrong because DNS filter operates independently of web filter rating; even if DNS filter allows the domain, the web filter profile's rating decision (block) would still apply unless overridden. Option D is wrong because an outdated FortiGuard database would cause 'rating not allow' for all users, not selectively for some, and the debug output would typically show 'rating error' or 'unrated' rather than a clear 'rating not allow'.

62
MCQmedium

A company policy requires that all web searches by employees use safe search. Which setting should be configured in the web filtering profile?

A.Enable 'Restrict YouTube Access'
B.Create a URL filter to block URLs with 'safe search'
C.Enable 'Enforce 'Safe Search' on Google, Bing, and Yahoo'
D.Set the 'Action' for FortiGuard categories to 'Warning'
AnswerC

Enabling 'Enforce Safe Search on Google, Bing, and Yahoo' is the correct FortiGate web filtering option because it actively forces these three search engines to use their safe search settings by rewriting URLs, setting cookies, or leveraging FortiGuard's search engine integration. Even if a user attempts to disable safe search in their browser, the FortiGate intercepts the request and ensures the search results are filtered at the network level, thereby meeting the company policy requirement.

Why this answer

The 'Enforce Safe Search' setting in a FortiGate web filtering profile forces Google, Bing, and Yahoo to use their built-in safe search parameters (e.g., &safe=active for Google). This ensures that all web searches from the network comply with the company policy by appending the required query strings to search URLs, blocking explicit content at the search engine level.

Exam trap

The trap here is that candidates often confuse 'Enforce Safe Search' with URL filtering or category blocking, assuming that blocking or warning on categories like 'Search Engines' would achieve the same result, but safe search enforcement is a specific feature that modifies search queries rather than blocking access.

How to eliminate wrong answers

Option A is wrong because 'Restrict YouTube Access' only controls YouTube content (e.g., enforcing strict or moderate mode), not general web search safe search. Option B is wrong because creating a URL filter to block URLs containing 'safe search' would block access to safe search configuration pages, not enforce safe search on search engines. Option D is wrong because setting the 'Action' for FortiGuard categories to 'Warning' only displays a warning page for categorized sites, it does not modify search engine behavior to enforce safe search.

63
Multi-Selectmedium

An administrator wants to block all peer-to-peer (P2P) file sharing applications such as BitTorrent and eMule on the network. Which THREE steps should the administrator take?

Select 3 answers
A.Configure a web filter profile to block P2P websites
B.Enable deep inspection on the firewall policy to detect encrypted P2P traffic
C.Create an application control profile with the P2P category blocked
D.Apply the application control profile to a firewall policy allowing internet access
E.Enable antivirus to block P2P protocols
AnswersB, C, D

Deep inspection is necessary because many P2P applications encrypt their sessions with TLS/SSL, which hides protocol fingerprints from normal flow-based inspection. By acting as a man-in-the-middle and terminating the TLS connection, the FortiGate can re-inspect the decrypted payload with its application control signatures and identify the P2P protocol. Note that deep inspection alone only makes the traffic visible; it must be paired with an application control profile that blocks the P2P category to actually deny it.

Why this answer

Enabling deep inspection on the firewall policy allows the FortiGate to decrypt and inspect encrypted P2P traffic, such as BitTorrent or eMule using TLS/SSL. Without deep inspection, the firewall cannot see inside encrypted packets to identify P2P signatures, making application control ineffective for encrypted flows.

Exam trap

The trap here is that candidates often think web filtering or antivirus can block P2P traffic, but only application control combined with deep inspection can identify and block the actual P2P protocol signatures, especially when encrypted.

64
Drag & Dropmedium

Drag and drop the steps to capture traffic on a FortiGate interface using the CLI into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The sniffer command syntax is diagnose sniffer packet <interface> <filter> <verbose> <count>.

65
MCQmedium

A network administrator notices that HTTP traffic is being scanned by the antivirus profile, but HTTPS traffic to the same web server is not being scanned. The firewall policy has the antivirus profile applied and SSL inspection is set to 'certificate-inspection'. What is the most likely reason HTTPS traffic is not being scanned?

A.Certificate inspection does not decrypt the traffic, so the antivirus scanner cannot inspect the payload.
B.The antivirus profile is configured in flow mode, which does not support scanning HTTPS traffic.
C.The web server is not using a cipher supported by the FortiGate.
D.The FortiGate is using proxy-based inspection, which does not support HTTPS scanning.
AnswerA

Certificate inspection only validates the server certificate's identity and trust chain; it does not terminate the TLS session or decrypt the stream. Consequently, the FortiGate forwards the encrypted HTTP payload unchanged, and the antivirus engine sees only ciphertext. Since malware signatures cannot be matched against encrypted bytes, the antivirus profile simply cannot inspect what it cannot see, which is exactly why HTTP traffic appears to bypass scanning.

Why this answer

Certificate inspection only validates the SSL/TLS certificate without decrypting the traffic. Since the antivirus scanner requires access to the plaintext payload to detect threats, it cannot scan HTTPS traffic when only certificate inspection is configured. This is why HTTP traffic is scanned but HTTPS traffic is not.

Exam trap

The trap here is that candidates often assume 'certificate-inspection' implies some level of content scanning, but it only validates the certificate and does not decrypt the traffic for security profile inspection.

How to eliminate wrong answers

Option B is wrong because flow mode does support scanning HTTPS traffic when SSL inspection is configured to decrypt the traffic; the issue here is the lack of decryption, not the inspection mode. Option C is wrong because cipher support is irrelevant when the traffic is not being decrypted at all; the FortiGate never attempts to negotiate a cipher for inspection. Option D is wrong because proxy-based inspection actually supports HTTPS scanning with full SSL decryption; the problem is that certificate inspection does not decrypt, regardless of the inspection mode.

66
MCQeasy

Which inspection mode in the antivirus profile processes traffic by buffering the entire file before scanning, allowing more thorough detection but potentially increasing latency?

A.Proxy-based inspection
B.Deep inspection
C.DNS inspection
D.Flow-based inspection
AnswerA

Proxy-based inspection is the correct mode because it buffers the entire file in memory before scanning, allowing FortiOS to perform a thorough, full-file signature analysis. This enables detection of threats embedded deep within archives, compressed files, or multi-part executables that could evade streaming methods. As a result, it provides the highest fidelity for antivirus detection, albeit with added latency proportional to file size.

Why this answer

Proxy-based inspection in the antivirus profile buffers the entire file in memory before scanning, enabling thorough detection of threats like polymorphic malware or embedded exploits. This mode reassembles the full data stream, allowing the FortiGate to perform deep content analysis, but it introduces higher latency due to the buffering and reassembly process.

Exam trap

The trap here is that candidates often confuse 'deep inspection' with 'proxy-based inspection' because both involve thorough analysis, but deep inspection specifically refers to SSL/TLS decryption, not the file buffering mechanism in antivirus profiles.

How to eliminate wrong answers

Option B is wrong because deep inspection is a broader security profile feature (e.g., SSL/TLS inspection) that decrypts traffic for scanning, not a specific antivirus inspection mode that buffers files. Option C is wrong because DNS inspection is a separate security profile for filtering DNS queries and responses, not related to file buffering or antivirus scanning. Option D is wrong because flow-based inspection processes packets in real-time without buffering the entire file, reducing latency but sacrificing the thorough detection that proxy-based mode provides.

67
Multi-Selectmedium

A FortiGate administrator wants to block access to Facebook for all internal users. However, the administrator must ensure that the CEO's computer (IP 10.0.0.100) is exempted. Which TWO steps should the administrator take? (Choose two.)

Select 2 answers
A.Add the CEO's IP to the application control profile's 'exempt IP' list.
B.Configure an IP exemption in the application control profile.
C.Create an application control profile with a rule to block 'Facebook' and apply it to the firewall policy for all users.
D.Create a firewall policy above the blocking policy that allows traffic from the CEO's IP to Facebook, with no application control profile.
E.Use a web filter profile with a URL block for 'facebook.com' instead of application control.
AnswersC, D

Creating an application control profile with a rule that blocks the 'Facebook' application signature and assigning that profile to the firewall policy for all users is the correct method. FortiOS application control uses deep packet inspection and regularly updated signatures to identify Facebook traffic even when it uses alternate domains or IP addresses. Because the profile is applied to the policy, every matching session that is detected as Facebook will be blocked for all users.

Why this answer

Option C is correct because the administrator must first create an application control profile containing a rule that blocks the Facebook application (Facebook is recognized as an application signature, not merely a URL), and then apply that profile to the firewall policy covering all internal users so the block is enforced. Option D is correct because FortiGate evaluates firewall policies top-down, so placing a policy above the blocking policy that permits traffic sourced from the CEO's IP 10.0.0.100 and does not reference the application control profile ensures the CEO's traffic is matched and allowed before the blocking policy is reached. Option A is incorrect because application control profiles in FortiOS do not provide an 'exempt IP' list; exemptions are achieved through policy ordering, not profile-level IP exceptions.

Option B is incorrect for the same reason—there is no per-IP exemption setting inside an application control profile. Option E is incorrect because a web filter URL block for facebook.com would not reliably block the Facebook application (which can use multiple domains and non-HTTP traffic) and does not address the CEO exemption requirement.

Exam trap

NSE4 often tests the misconception that application control profiles support IP exemptions, when in fact exemptions are achieved through firewall policy ordering and source IP matching.

68
MCQhard

An administrator has configured DLP sensors to detect credit card numbers in outgoing traffic. However, the administrator notices that traffic containing credit card numbers is still passing through undetected. The firewall policy uses flow-based inspection. What is the MOST likely reason DLP is not detecting the data?

A.DLP requires proxy-based inspection to perform data leakage detection.
B.The DLP sensor is not applied to the correct firewall policy.
C.The DLP sensor is configured with the wrong regular expression.
D.The credit card numbers are encrypted by SSL and deep inspection is not enabled.
AnswerA

DLP inspection requires proxy-based inspection because the firewall must reassemble and scan the full payload; flow-based inspection forwards packets without buffering content, so credit card patterns pass undetected. This satisfies the stem's constraint that the policy uses flow-based inspection.

Why this answer

DLP requires proxy-based inspection to buffer and analyze the content. Flow-based inspection does not support DLP.

69
MCQmedium

A company with 500 users has a FortiGate 1000D running FortiOS 7.2. They have configured full SSL inspection and web filtering to block malware and phishing sites. The administrator receives complaints that some users cannot access a legitimate business website (https://vendor.example.com). The administrator checks the FortiGate logs and sees that the connection is allowed by the firewall policy and web filter. However, the user's browser shows 'ERR_CERT_AUTHORITY_INVALID'. The administrator verifies that the FortiGate's CA certificate is installed on all client machines. Further investigation reveals that the vendor's website uses a certificate signed by a private CA that is not trusted by the FortiGate. The administrator wants to resolve the issue without disabling SSL inspection for the whole website or compromising security. What should the administrator do?

A.Create an SSL exemption for the vendor's domain in the SSL inspection profile.
B.Import the vendor's private CA certificate into the FortiGate's trusted root CA store.
C.Change the SSL inspection profile to certificate inspection only.
D.Install the vendor's CA certificate on the client machines.
AnswerB

Importing the vendor's private CA certificate into the FortiGate's trusted root CA store is the correct fix because the FortiGate acts as a TLS man-in-the-middle and must validate the vendor's server certificate chain before it can generate an on-the-fly session certificate for the client. Once that CA is trusted, the FortiGate successfully validates the vendor's certificate, completes its upstream TLS connection, and issues a client-facing certificate signed by the FortiGate's own CA, restoring full inline inspection without any warning. This centralized approach also avoids needing to touch the 500 client machines.

Why this answer

The FortiGate cannot validate the vendor's certificate because its private CA is not in the FortiGate's trusted root store. By importing that CA certificate into the FortiGate's trusted root CA store, the FortiGate will trust the vendor's certificate chain, allowing full SSL inspection to proceed without errors. This resolves the ERR_CERT_AUTHORITY_INVALID error while maintaining security inspection for the domain.

Exam trap

The trap here is that candidates often assume the client-side CA certificate installation is sufficient, but the FortiGate itself must also trust the server's issuing CA to perform full SSL inspection without errors.

How to eliminate wrong answers

Option A is wrong because creating an SSL exemption bypasses inspection entirely for the domain, which compromises security by allowing encrypted traffic to pass without inspection. Option C is wrong because changing to certificate inspection only would disable deep packet inspection for all traffic, reducing security posture and not specifically addressing the untrusted CA issue. Option D is wrong because the client machines already have the FortiGate's CA certificate installed; the issue is that the FortiGate itself does not trust the vendor's private CA, so installing it on clients does not fix the server-side validation failure.

70
MCQhard

An administrator enables deep inspection for HTTPS traffic. Users report that they cannot access some websites because of certificate errors. The administrator wants to override these errors and allow access. What should be configured?

A.Disable certificate verification in the deep inspection profile
B.Add the websites to the 'FortiGuard category' allow list
C.Configure the web filter to allow these websites
D.Add the websites to the 'SSL/SSH exemption' list in the deep inspection profile
AnswerD

Adding the websites to the SSL/SSH exemption list in the deep inspection profile is the correct method because it instructs the FortiGate to skip decryption for those exact destinations. The FortiGate then forwards the TLS handshake untouched, so the browser sees the original site certificate and no certificate validation error occurs. All other HTTPS traffic continues to be deeply inspected, preserving overall security while solving the compatibility problem.

Why this answer

In FortiOS, deep inspection can generate certificate errors for sites with self-signed or mismatched certificates. To allow access despite errors, the administrator can add the affected domains to the 'SSL/SSH exemption' list in the deep inspection profile. This exempts those sites from deep inspection, avoiding the certificate error.

71
MCQeasy

What is the purpose of enabling 'DNS filter' in a security profile?

A.To cache DNS responses for faster browsing
B.To prevent DNS tunneling attacks
C.To enforce safe search on search engines
D.To block DNS queries to known malicious domains
AnswerD

A DNS filter enforces a security policy by matching DNS queries against a real-time feed of malicious domains, including those used for malware, ransomware, phishing, and botnet C2 infrastructure. When a client attempts to resolve such a domain, the filter returns a denial (either a block page IP or a sinkhole IP) instead of the real record, preventing the connection before it is established. This proactive approach stops threats at the earliest stage of the communication chain, even if the client has no other security controls.

Why this answer

FortiGate's DNS filter security profile inspects DNS queries and blocks those destined for domains categorized as malicious (botnets, phishing, malware C2) using FortiGuard's DNS threat intelligence. This prevents clients from resolving and reaching known-bad domains, cutting off the first step of many attacks.

Exam trap

NSE4 often tests the difference between the DNS filter profile's core purpose (blocking malicious domain resolution) and its optional sub-features (safe search, caching) — candidates pick 'safe search' or 'DNS tunneling' because those appear in the profile's settings, missing the primary intent.

How to eliminate wrong answers

Option A is wrong because DNS caching is a resolver/performance function, not the purpose of the DNS filter security profile. Option B is wrong because while DNS filtering can disrupt some DNS tunneling by blocking malicious domains, preventing DNS tunneling specifically is not its stated purpose — that is better addressed by DNS inspection/DoS policies and anomaly detection. Option C is wrong because safe search enforcement is a separate DNS filter option (safe search for Google/Bing/YouTube) within the profile, not the profile's overall purpose.

72
MCQeasy

What is the purpose of the 'DNS Filter' feature on a FortiGate?

A.To block DNS queries to malicious domains based on FortiGuard category and allow/block lists.
B.To cache DNS queries for faster resolution.
C.To encrypt DNS traffic to prevent eavesdropping.
D.To filter the content of DNS responses from legitimate servers.
AnswerA

DNS Filter on FortiGate intercepts DNS queries and evaluates the requested domain against FortiGuard's threat intelligence categories, as well as administrator-defined allow and block lists. If the domain is categorized as malicious or prohibited, the FortiGate drops the query or returns a spoofed response, preventing the client from resolving the domain to an IP address. This is a proactive security control because it stops the connection before any traffic reaches the malicious server, even if the client already knows the IP via DNS pinning or a hosts file.

73
MCQeasy

What is the PRIMARY purpose of enabling 'Safe Search' in a web filter profile?

A.To block all search engines
B.To prevent users from using HTTPS search engines
C.To enforce safe search settings on supported search engines like Google and Bing
D.To log all search queries
AnswerC

The core purpose of safe search is to enforce content filtering on supported search engines such as Google and Bing by appending safe search parameters or using DNS-based enforcement. This compels the search engine to omit adult or explicit material from result pages, aligning with an organization's acceptable use policy. FortiGate applies this through firewall policy profiles, ensuring users cannot disable it client-side.

Why this answer

Safe Search enforces the safe search feature of popular search engines (e.g., Google, Bing) to filter explicit content from search results. It does not block search engines or HTTPS.

74
MCQeasy

Which IPS detection method uses a baseline of normal traffic and alerts when deviations exceed a threshold?

A.Anomaly detection
B.Rate-based detection
C.Signature-based detection
D.Protocol decode-based detection
AnswerA

Anomaly detection is the IPS technique that builds a statistical or machine-learning baseline of 'normal' network behavior by observing traffic patterns over time, including metrics like packet sizes, protocols, and session flows. Once the baseline is established, any significant deviation from that learned profile is flagged as an anomaly, potentially indicating a zero-day exploit or insider threat. This is the only method listed that fundamentally depends on a baseline of normal traffic to operate.

Why this answer

Anomaly detection establishes a baseline of normal network traffic patterns and triggers alerts when observed traffic deviates significantly from that baseline. This method is effective for identifying unknown or zero-day attacks that do not match predefined signatures, as it relies on statistical or behavioral analysis rather than fixed patterns.

Exam trap

The trap here is that candidates often confuse rate-based detection with anomaly detection, but rate-based detection uses fixed or adaptive thresholds on event counts (e.g., SYN flood rate) rather than a learned baseline of normal traffic behavior.

How to eliminate wrong answers

Option B (Rate-based detection) is wrong because it monitors the frequency of specific events (e.g., connection attempts per second) and triggers when a threshold is exceeded, but it does not establish a baseline of normal traffic; it uses static or dynamic rate limits. Option C (Signature-based detection) is wrong because it compares traffic against predefined patterns or signatures of known attacks, not against a baseline of normal behavior. Option D (Protocol decode-based detection) is wrong because it analyzes protocol compliance and anomalies within protocol fields (e.g., malformed packets), but it does not learn normal traffic patterns over time.

75
MCQeasy

Which of the following best describes the function of FortiGuard web filtering categories?

A.They are used to quarantine infected files
B.They block specific IP addresses known for hosting malware
C.They provide a list of allowed websites only
D.They categorize websites to allow granular control over access based on content type
AnswerD

FortiGuard web-filtering categories assign websites to taxonomy classes, such as 'Social Networking', 'Video/Audio', and 'Webmail', based on the site's actual content. This allows FortiGate administrators to construct IPv4/IPv6 firewall policies and proxy policies that permit or deny entire content categories, optionally with per-user or per-time overrides. Because the categorization is content-driven, it enables fine-grained access control that adapts to the constantly changing web rather than relying on a simple list of URLs.

Why this answer

FortiGuard web filtering categories are pre-classified buckets (e.g., Social Networking, Malware, Phishing, Streaming Media) that map URLs/domains to content types. Administrators use these categories in web filter profiles to allow, block, monitor, or warn on entire classes of sites, giving granular, policy-driven control without maintaining manual URL lists. This is the core function of the FortiGuard category database.

Exam trap

The trap is conflating web filtering categories with other security profiles — candidates often pick 'block specific IPs' or 'quarantine files' because those sound like security functions, but categories are strictly about content classification for access control.

How to eliminate wrong answers

Option A is wrong because quarantining infected files is the job of the antivirus profile (or sandboxing), not web filtering categories. Option B is wrong because blocking specific malicious IPs is handled by IP reputation/blocklists or DNS filter, not by URL content categories. Option C is wrong because FortiGuard categories classify both allowed and blocked content — they are not an allow-list-only mechanism; the admin decides the action per category.

Page 1 of 3 · 182 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security Profiles questions.