IPS Sensor Target Default Not Blocking Attacks in Flow-Based Inspection
A FortiGate is configured with an IPS profile to protect a web server. The administrator notices that some attacks are not being detected. The IPS signature database is up to date. What should the administrator check first?
⚠ Common exam trap
NSE4 often tests the misconception that IPS detection depends solely on signature database updates or sensor configuration, while overlooking the critical step of applying the IPS profile to the correct firewall policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the IPS profile is applied to the firewall policy that handles traffic to the web server.
The most common reason an IPS profile fails to detect attacks is that the profile is not actually applied to the firewall policy processing the traffic. In FortiGate, an IPS sensor must be referenced in the security profile settings of the specific firewall policy that permits traffic to the web server. Without this binding, the IPS engine never inspects the packets, regardless of signature database freshness or sensor configuration. Therefore, verifying policy association is the first and most fundamental troubleshooting step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the severity level of the IPS sensor.
Why it's wrong here
Increasing the severity level of an IPS sensor only adjusts which signatures are considered high priority and how many logs are generated, not whether detection occurs. Detection is governed by signature matching against the traffic stream, and severity thresholds primarily affect alerting and default response. If the traffic isn't being inspected because the IPS profile isn't attached to the relevant firewall policy, a higher severity setting will have no effect on whether an attack is identified.
- ✓
Ensure the IPS profile is applied to the firewall policy that handles traffic to the web server.
Why this is correct
To protect a web server, the IPS profile must be attached to the firewall policy that controls access to that server, and that policy must actually match the traffic's source, destination, port, and interface. Without this attachment, the FortiGate forwards traffic based on the policy's action alone and never passes the packets to the IPS engine for inspection. Verify that the policy order places this rule before any catch-all policy, and confirm that the 'Security Profiles' section lists the desired IPS sensor; otherwise, the sensor is effectively dormant.
- ✗
Disable flow-based inspection and enable proxy-based inspection.
Why it's wrong here
Switching from flow-based to proxy-based inspection, or vice versa, does not change the underlying signature database or enable detection of new attacks. Flow-based inspection is a single-pass architecture that scales well, while proxy-based uses full proxy and may offer additional protocol validation, but both modes apply the same IPS signatures and are equally capable of pattern matching. If a signature fails to trigger, the cause is more likely a missing policy association or an outdated signature set, not the inspection mode.
- ✗
Change the IPS signature action from 'default' to 'block'.
Why it's wrong here
Changing a signature's action from 'default' to 'block' alters the response when a match occurs—it does not turn on detection. Detection happens during traffic inspection, and the action only dictates whether the matched traffic is passed, dropped, or reset. Furthermore, 'default' action commonly inherits the signature's vendor-recommended blocking behavior, so overriding it may have little practical effect; if the profile is not applied to the correct policy, no signature will ever trigger regardless of the action setting.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.