Courseiva

NSE4 · topic practice

Security Profiles practice questions

This domain covers FortiGate security profiles: antivirus, web filter, application control, IPS, email filter, DLP, and SSL inspection. Questions test configuration, CLI diagnostics like 'diagnose debug rating', and troubleshooting false positives or certificate trust issues. You must know how profiles interact with firewall policies and how to tune them for accurate detection.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Security Profiles

What the exam tests

What to know about Security Profiles

Be able to configure and troubleshoot FortiGate security profiles, especially SSL inspection and web filtering. The single most important thing: ensure the FortiGate CA certificate is trusted on clients when using deep SSL inspection, or HTTPS sites will break.

Web filter actions, safe search, and FortiGuard category rating lookups

Deep SSL inspection certificate trust and exempting sites from inspection

Email filter spam blocking and reducing false positives with allow lists

Application control and IPS sensor configuration within firewall policies

Watch out for

Common Security Profiles exam traps

  • ▸Forgetting that deep SSL inspection requires the FortiGate CA certificate to be trusted on client devices, or sites will fail to load.
  • ▸Assuming 'diagnose debug rating' timeouts are always a FortiGate issue, when the most likely cause is no route or DNS to FortiGuard servers.
  • ▸Believing email filter spam blocking is perfect; false positives require tuning with allow lists or adjusting spam action thresholds.

Practice set

Security Profiles questions

20 questions · select your answer, then reveal the explanation

A network administrator notices that users cannot access HTTPS websites after enabling SSL inspection. The firewall policy allows the traffic, and the certificate is trusted on the clients. What is the most likely cause?

A company wants to block downloads of executable files via HTTP and HTTPS while allowing other content. Which combination of security profiles should be applied to the firewall policy?

An administrator wants to inspect SSL traffic to a specific finance application that uses a custom port (9443) and a self-signed certificate. Which configuration is required?

Which TWO web filtering features can be used to block access to malicious websites? (Choose two.)

Refer to the exhibit. The policy applies deep inspection, but users cannot access any HTTPS websites. The FortiGate CA certificate is installed on clients. What is the most likely cause?

Exhibit

Refer to the exhibit.

config firewall policy
    edit 1
        set name "Web Access"
        set srcintf "internal"
        set dstintf "wan"
        set srcaddr "all"
        set dstaddr "all"
        set action accept
        set schedule "always"
        set service "HTTPS"
        set ssl-ssh-profile "deep-inspection"
        set utm-status enable
        set av-profile "default"
        set webfilter-profile "strict"
    next
end
Question 6mediummultiple choice
Review the full subnetting walkthrough →

A school uses FortiGate for web filtering. They want to block social media sites for students during class hours (8 AM to 3 PM) but allow access for teachers at all times. The network has a single internet connection and all users are in the same subnet. The administrator created a firewall policy for students (source IP range 192.168.1.100-200) and another for teachers (source IP range 192.168.1.10-50). The student policy has a web filter profile that blocks social media. However, teachers are also being blocked from social media during class hours. What is the most likely cause?

A security engineer is designing an application control policy for a corporate network. The goal is to allow Microsoft Teams for business use but block personal use of other collaboration apps like Zoom and Slack. The engineer configures an application control profile with a rule to 'monitor' Microsoft Teams and 'block' Zoom and Slack. However, users report that Zoom is still working. What is the most likely reason?

During a security audit, an administrator finds that an IPS sensor configured with a 'block' action for a critical vulnerability signature is not blocking the associated traffic. The traffic matches the signature, but the action appears as 'pass' in the logs. The IPS sensor is applied to a firewall policy that also has application control enabled. What is the most likely cause?

Which TWO are valid actions for an application control rule?

Question 10mediummultiple choice
Read the full Security Profiles explanation →

An administrator configures a web filter profile to block the 'Phishing' category. Users still report receiving phishing emails with links that bypass the filter. What is the most likely reason?

Which THREE of the following are valid methods to exclude certain HTTPS traffic from SSL inspection on a FortiGate?

Question 12mediummultiple choice
Read the full Security Profiles explanation →

A company wants to block all peer-to-peer (P2P) traffic using Application Control on their FortiGate. They have enabled the application control profile, but users can still download files via BitTorrent. What is the most likely reason?

Refer to the exhibit. An administrator is troubleshooting why SSL inspection is not working for web traffic. The policy shown is the only policy matching the traffic. What is the most likely reason SSL inspection is failing?

Exhibit

Refer to the exhibit.

config firewall policy
    edit 1
        set name "SSL-Inspection"
        set srcintf "wan1"
        set dstintf "internal"
        set srcaddr "all"
        set dstaddr "all"
        set action accept
        set schedule "always"
        set service "ALL"
        set utm-status enable
        set ssl-ssh-profile "deep-inspection"
        set profile-protocol-options "default"
        set av-profile "default"
        set webfilter-profile "default"
    next
end
Question 14mediumdrag order
Read the full VPN explanation →

Drag and drop the steps to configure IPsec VPN phase 1 settings on FortiGate into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each FortiGate CLI command to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Displays current system resource usage

Tests network connectivity to a host

Traces packet flow through the firewall

Displays the entire running configuration

Resets the device to factory defaults

Question 16mediummultiple choice
Read the full Security Profiles explanation →

A network administrator wants to allow employees to access a specific web application but block all other application traffic. The administrator creates a firewall policy with an application control profile that allows the desired application. However, employees can still access other applications. What is the MOST likely reason?

A FortiGate administrator is troubleshooting an issue where users cannot access a legitimate website that is categorized as 'Pornography' by FortiGuard. The web filter profile is configured to block that category. The administrator wants to allow access for a specific user group without modifying the global web filter profile. What is the BEST approach?

Question 18mediummultiple choice
Read the full Security Profiles explanation →

A FortiGate administrator is configuring SSL deep inspection for a firewall policy that handles traffic to multiple internal servers. Some servers have self-signed certificates. The administrator wants to avoid certificate errors for users. What configuration is recommended?

An administrator has configured an IPS profile with an anomaly detection sensor for 'tcp_syn_flood'. After applying the profile to a firewall policy, users report intermittent connectivity issues. The administrator runs 'diagnose ips anomaly list' and sees entries for 'tcp_syn_flood' with action 'pass'. What is the MOST likely cause of the connectivity issues?

A FortiGate administrator is configuring a data leak prevention (DLP) profile to prevent the leakage of social security numbers (SSNs) via email. Which TWO settings must be configured in the DLP profile?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security Profiles sessions

Start a Security Profiles only practice session

Every question in these sessions is drawn from the Security Profiles domain — nothing else.

Related practice questions

Related NSE4 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the NSE4 exam test about Security Profiles?
Be able to configure and troubleshoot FortiGate security profiles, especially SSL inspection and web filtering. The single most important thing: ensure the FortiGate CA certificate is trusted on clients when using deep SSL inspection, or HTTPS sites will break.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security Profiles questions in a focused session?
Yes — the session launcher on this page draws every question from the Security Profiles domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other NSE4 topics?
Use the topic links above to move to related areas, or go back to the NSE4 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the NSE4 exam covers. They are not copied from any real exam or dump site.