Key Web Filtering Features for Malicious Site Blocking
Which FortiGate feature allows you to block access to specific URL categories such as 'Social Media' or 'Gambling'?
⚠ Common exam trap
Many exam-takers confuse Application Control with Web Filtering, as both can block 'Social Media' but Application Control blocks based on application signatures (e.g., Facebook app traffic) while Web Filtering blocks based on URL categories, and candidates often overlook that Application Control cannot block a website accessed via a browser if the URL category is not explicitly blocked.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Web Filtering
FortiGate's Web Filtering feature uses URL rating and category databases (e.g., FortiGuard) to block access to entire categories like 'Social Media' or 'Gambling' based on the destination URL. This is distinct from content inspection; it operates at the HTTP/HTTPS request level by matching the requested URL against predefined or custom category lists.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Web Filtering
Why this is correct
Web Filtering on FortiGate leverages the FortiGuard web filtering database to classify URLs into categories (e.g., social media, malware, phishing) and enforce per-policy allow, block, or warn actions based on those categories or a custom URL list. This directly controls which websites users can access, making it the correct feature for blocking specific sites. It can also be combined with local overrides and wildcard FQDN entries to fine-tune granular access control.
- ✗
Antivirus
Why it's wrong here
Antivirus (AV) scanning inspects files and traffic for known malware signatures, heuristics, and sandboxing behavior, but it does not categorize or deny individual URLs or domains. While a blocked URL might coincidentally hide malware, AV is a security control against malicious payloads, not an access control mechanism for web navigation. Its placement in a policy protects against threats, yet it cannot enforce URL-policy decisions.
- ✗
Intrusion Prevention System (IPS)
Why it's wrong here
IPS detects and blocks network-layer threats by matching packet payloads against vulnerability signatures and behavioral anomalies, such as exploit attempts against web servers. It does not maintain a URL category database nor evaluate the web address a user requests; its focus is on the attack packet content, not the site origin. Thus, an IPS rule cannot be used to deny access to a specific website by name or category.
- ✗
Application Control
Why it's wrong here
Application Control identifies network traffic by application signatures (e.g., Facebook, Skype) and can allow, deny, or shape bandwidth for those applications, regardless of the underlying URL or domain. It does not parse or classify web addresses into content categories, so it cannot block a specific website like www.example.com unless that site is uniquely tied to a recognized application. Its scope is application identity, not URL classification.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A network administrator wants to prevent users from accessing known malicious websites using FortiGate. Which security profile should be applied to the firewall policy to achieve this goal?
easy- A.Antivirus profile
- B.Application control profile
- C.IPS profile
- ✓ D.Web filtering profile
Why D: Web filtering profile. FortiGate's web filtering profile uses URL rating and category-based filtering to block access to known malicious websites by leveraging FortiGuard's real-time threat intelligence. This is the specific security profile designed to control web access based on URL reputation, including blocking malicious URLs.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.