Courseiva
Security Profiles →easyMultiple Choice

NSE4 Security Profiles Practice Question

What is the PRIMARY purpose of enabling 'Safe Search' in a web filter profile?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To enforce safe search settings on supported search engines like Google and Bing

Safe Search enforces the safe search feature of popular search engines (e.g., Google, Bing) to filter explicit content from search results. It does not block search engines or HTTPS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To block all search engines

    Why it's wrong here

    Safe search is not designed to block all search engines. That would require a full URL filtering or web category block action, which prevents access to any search engine entirely. Safe search instead permits access to supported search engines while instructing them to strip explicit or adult content from results, so the objective is content filtering, not connectivity blocking.

  • ✗

    To prevent users from using HTTPS search engines

    Why it's wrong here

    Safe search does not prevent HTTPS usage; rather, it works alongside HTTPS to modify search requests on supported engines. FortiGate enforces safe search by rewriting the URL or injecting a query parameter (e.g., `safe=active`) for engines like Google and Bing, which does not require blocking encryption. Blocking HTTPS would be a separate SSL inspection or policy decision, unrelated to safe search functionality.

  • ✓

    To enforce safe search settings on supported search engines like Google and Bing

    Why this is correct

    The core purpose of safe search is to enforce content filtering on supported search engines such as Google and Bing by appending safe search parameters or using DNS-based enforcement. This compels the search engine to omit adult or explicit material from result pages, aligning with an organization's acceptable use policy. FortiGate applies this through firewall policy profiles, ensuring users cannot disable it client-side.

  • ✗

    To log all search queries

    Why it's wrong here

    Safe search is not a logging mechanism; it does not capture or record user queries. Search query logging is performed via DNS logging, application control, or data leak prevention features, which record domain names or application traffic. Safe search solely modifies the search request to request filtered results, leaving any logging to separate security features.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.