Courseiva
Security Profiles →easyMultiple Choice

NSE4 Security Profiles Practice Question

What is the purpose of enabling 'DNS filter' in a security profile?

⚠ Common exam trap

NSE4 often tests the difference between the DNS filter profile's core purpose (blocking malicious domain resolution) and its optional sub-features (safe search, caching) — candidates pick 'safe search' or 'DNS tunneling' because those appear in the profile's settings, missing the primary intent.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To block DNS queries to known malicious domains

FortiGate's DNS filter security profile inspects DNS queries and blocks those destined for domains categorized as malicious (botnets, phishing, malware C2) using FortiGuard's DNS threat intelligence. This prevents clients from resolving and reaching known-bad domains, cutting off the first step of many attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To cache DNS responses for faster browsing

    Why it's wrong here

    DNS caching is a function of recursive resolvers or local DNS forwarders to reduce latency and network load by storing previously resolved queries. A DNS filter, on the other hand, inspects DNS queries against threat intelligence categories and blocks resolutions to domains associated with malware, phishing, or command-and-control (C2). While a security policy might include DNS caching for performance, that is not the purpose of enabling DNS filtering—the filter prioritizes security by denying malicious lookups, not improving browsing speed.

  • ✗

    To prevent DNS tunneling attacks

    Why it's wrong here

    DNS tunneling is an attack technique where malicious data is encoded in DNS queries and responses to exfiltrate information or establish a covert C2 channel, often evading traditional firewalls. Blocking this requires deep inspection of DNS payloads and protocol anomalies, which is performed by IPS signatures or application control engines that detect unusual DNS traffic patterns, not by the DNS filter itself. A DNS filter focuses on evaluating the reputation of the queried domain name, so it can block known bad domains but cannot identify a legitimate-looking domain acting as a tunnel endpoint without additional behavioral heuristics.

  • ✗

    To enforce safe search on search engines

    Why it's wrong here

    Safe search enforcement involves modifying HTTP/S requests to search engine result pages (e.g., appending parameters like safe=active) or leveraging browser-based policies to filter adult content from search results. Web filtering operates at the HTTP layer, where it can inspect URLs, content categories, and even rewrite or block search results. A DNS filter, by contrast, only decides whether to resolve a queried domain to an IP address based on domain reputation; it sits at layer 3/4 and cannot alter the content of a search page or inject URL parameters, making it unsuitable for enforcing safe search.

  • ✓

    To block DNS queries to known malicious domains

    Why this is correct

    A DNS filter enforces a security policy by matching DNS queries against a real-time feed of malicious domains, including those used for malware, ransomware, phishing, and botnet C2 infrastructure. When a client attempts to resolve such a domain, the filter returns a denial (either a block page IP or a sinkhole IP) instead of the real record, preventing the connection before it is established. This proactive approach stops threats at the earliest stage of the communication chain, even if the client has no other security controls.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.