Courseiva

NSE4 System and Network Administration Practice Question

Match each Fortinet security feature to its primary function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Detects and prevents network intrusions

Identifies and controls application traffic

Blocks access to malicious or unauthorized websites

Scans and removes malware from traffic

Decrypts and inspects encrypted traffic

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Antivirus: Scans files and traffic for known malware signatures.

The correct matches are: Antivirus scans for malware, IPS detects network attacks, Application Control identifies applications, Web Filtering blocks websites. Common confusions include mixing antivirus with anti-spam and IPS with antivirus.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Antivirus: Scans files and traffic for known malware signatures.

    Why this is correct

    Antivirus is a critical UTM component that uses signature-based detection to examine files, email attachments, and live traffic for known malware patterns, also incorporating heuristics and sandbox integration for unknown threats. It operates at the file and byte level, comparing hashes and signatures against FortiGuard's malware database. Thus, the definition correctly captures its primary function in Fortinet's layered security architecture.

  • ✓

    IPS: Detects and blocks network-based attacks.

    Why this is correct

    The Intrusion Prevention System (IPS) performs deep packet inspection, analyzing protocol fields and traffic patterns to detect and block exploit attempts like buffer overflows, SQL injection, and port scans. Unlike antivirus, it works on network streams rather than individual files, using vulnerability signatures and anomaly detection. It can drop malicious packets or reset sessions in real time, making the stated definition of network-based attack detection accurate.

  • ✓

    Application Control: Identifies and controls application traffic regardless of port.

    Why this is correct

    Application Control goes beyond port-based classification by using application signatures, behavioral analysis, and protocol decoding to identify applications even when they hide on non-standard ports or tunnel through other protocols. This enables FortiGate to enforce granular policies per application, such as allowing social media but blocking file-sharing or P2P traffic. Its primary function is thus correctly identified as identifying and controlling application traffic regardless of port.

  • ✓

    Web Filtering: Blocks access to malicious or inappropriate websites.

    Why this is correct

    Web Filtering assesses HTTP and HTTPS requests against URL categories, domain reputation, and real-time FortiGuard intelligence to block access to phishing, malicious, or policy-violating websites. It operates at the URL layer, distinct from application-level controls, and supports user- and group-based policies. This makes blocking malicious or inappropriate websites the concise and accurate description of its role.

  • ✗

    Antivirus: Filters unwanted email messages.

    Why it's wrong here

    Filtering unwanted email messages is the role of FortiGate's AntiSpam feature, which evaluates sender reputation, message content, and SMTP transaction metadata to classify mail as spam or junk. While antivirus can scan email attachments for malware, it does not decide whether a message is unwanted based on content or sender. This statement misattributes a distinct UTM capability to antivirus, so it is incorrect.

  • ✗

    IPS: Scans files for malware.

    Why it's wrong here

    IPS does not scan files for malware; it is a network traffic analysis engine that detects attack sequences and exploit signatures within live packet flows. Malware scanning of files is the domain of antivirus, which performs static and heuristic analysis on stored or transiting files. Although both features integrate in Fortinet UTM to defend the attack chain, confusing their roles is inaccurate because IPS lacks file-based scanning capability.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.