NSE4 Security Profiles Practice Question
What is the purpose of the 'DNS Filter' feature on a FortiGate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To block DNS queries to malicious domains based on FortiGuard category and allow/block lists.
DNS Filter is part of Fortinet's UTM (Unified Threat Management) profiles and integrates with FortiGuard's dynamic domain categorization. When a DNS query passes through the FortiGate, the DNS Filter compares the query name against its in-memory cache of categorized domains, or performs a real-time rating lookup if needed. The action can be 'block', 'allow', or 'monitor', and for blocked domains it can return a custom IP (e.g., an internal warning page) or simply drop the packet. A key subtlety is that DNS Filter only works if the client's DNS traffic actually traverses the FortiGate, so clients must use the FortiGate as their DNS forwarder or have DNS inspection enabled for both UDP and TCP. Since DNS Over HTTPS (DoH) renders traditional DNS Filter blind, Fortinet pairs DNS Filter with application control and SSL inspection to catch encrypted channel attempts, yet the feature remains a critical first line of defense against DNS-based malware delivery and phishing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
To block DNS queries to malicious domains based on FortiGuard category and allow/block lists.
Why this is correct
DNS Filter on FortiGate intercepts DNS queries and evaluates the requested domain against FortiGuard's threat intelligence categories, as well as administrator-defined allow and block lists. If the domain is categorized as malicious or prohibited, the FortiGate drops the query or returns a spoofed response, preventing the client from resolving the domain to an IP address. This is a proactive security control because it stops the connection before any traffic reaches the malicious server, even if the client already knows the IP via DNS pinning or a hosts file.
- ✗
To cache DNS queries for faster resolution.
Why it's wrong here
Caching DNS responses locally is a functionality of recursive DNS servers or forwarders, such as the FortiGate's own DNS server service or the OS resolver cache, not the DNS Filter security profile. The DNS Filter does not store or reuse query results; it inspects each DNS request in real time for policy enforcement. Its purpose is blocking, not acceleration, and it adds no performance benefit for repeated queries, distinguishing it from a caching resolver.
- ✗
To encrypt DNS traffic to prevent eavesdropping.
Why it's wrong here
Encrypting DNS traffic to prevent eavesdropping is accomplished by protocols like DNS over TLS (DoT) or DNS over HTTPS (DoH), typically configured on DNS servers or forwarders. The DNS Filter feature in FortiOS does not perform encryption; it operates transparently on cleartext DNS queries (UDP/TCP port 53) as they pass through the firewall. Even if a client uses DoT/DoH, the DNS Filter cannot inspect the encrypted query payload, which is why FortiGate also offers separate DoT/DoH proxy capabilities.
- ✗
To filter the content of DNS responses from legitimate servers.
Why it's wrong here
The DNS Filter does not parse or validate the content of DNS records in responses from legitimate servers, such as A, AAAA, or TXT records; it only looks at the domain name being queried in the request. Its blocking decision is based solely on the domain's category, reputation, and administrator-defined lists, not on the response payload. Furthermore, filtering response content from legitimate servers would be a form of data inspection beyond DNS Filter's scope, which is why it never inspects response bodies.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.