Courseiva
Free · No account needed · No credit card

Fortinet NSE 4 Network Security Professional NSE4 Practice Test

773 questions with instant explanations, domain breakdown, and wrong-answer analysis. Built for the real exam.

Instant feedback after each answer
Full explanations included
Domain score breakdown
Real exam: 105 min
Pass mark: 650/1000

Sample questions with explanations

This is exactly what you see during practice — question, options, and a full explanation after you answer.

Q1Security Profilesmedium
Full explanation →

An administrator wants to prevent data leakage by blocking outbound emails that contain credit card numbers. Which security profile should be configured?

AEmail Filter profile
BWeb Filter profile
CAntivirus profile
DLP profileCorrect

DLP (Data Loss Prevention) profiles are specifically designed to inspect content such as credit card numbers in outbound emails and block them to prevent data leakage. While other profiles handle spam, web access, or malware, only DLP can perform pattern-based content inspection …Read full explanation

Q2Security Profileshard
Full explanation →

An administrator configures an application control profile to block 'Facebook' and 'Twitter' using application signatures. Users can still access Facebook via HTTPS. The firewall policy has application control enabled and SSL deep inspection is not configured. Why is Facebook not blocked?

AThe application signature for Facebook is not updated
BThe application control profile is configured in monitor-only mode
HTTPS traffic is encrypted and cannot be inspected without SSL deep inspectionCorrect
DFacebook uses a non-standard port that application control does not monitor

Without SSL deep inspection, the FortiGate cannot decrypt HTTPS traffic to inspect the application-layer payload. Application control relies on inspecting unencrypted traffic or using SSL inspection to identify applications within encrypted sessions. Since Facebook uses HTTPS, th…Read full explanation

Q3Security Profileshard
Full explanation →

An administrator wants to block users from uploading files to cloud storage services like Google Drive via HTTPS. Which security profile combination is required?

Application control profile to block cloud storage applications, with deep inspection enabledCorrect
BIPS profile to block file uploads to cloud services
CDNS filter to block Google Drive domain
DWeb filter profile with URL filter to block Google Drive

To block file uploads to cloud storage services like Google Drive over HTTPS, an application control profile is required because it can identify and control specific application actions (e.g., file uploads) within encrypted traffic. Deep inspection must be enabled to decrypt the …Read full explanation

Untimed Practice

Answer at your own pace. Explanation and domain tag shown immediately after each answer.

Timed Practice

Countdown timer starts immediately. Results and domain scores shown at the end — just like the real exam.

Why practice here?

Full explanations on every question

Not just the right answer — you get exactly why each wrong option is wrong, so you learn the concept, not the answer.

Domain score breakdown

After each session see your score by exam domain so you know exactly where to focus study time.

100% free, forever

No subscription, no trial, no email wall. Start a session in under 10 seconds.

Exam-style questions

Scenario-based, precise wording, realistic distractors — written to match what you actually see on exam day.

← All NSE4 questionsNSE4 exam guideStudy guidePractice by domain