NSE4 Security Profiles Practice Question
Which FortiGate security profile is BEST suited for blocking DNS queries to known malicious domains?
⚠ Common exam trap
NSE4 often tests the layer confusion between Web Filter (HTTP/HTTPS) and DNS Filter (DNS), so candidates pick Web Filter thinking it covers all domain-based blocking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS Filter profile
The DNS Filter profile on FortiGate is purpose-built to inspect DNS queries and block resolution of known malicious domains by comparing them against FortiGuard DNS threat intelligence. It operates at the DNS layer, so it stops the connection before it is even established. This is the most direct and efficient control for blocking DNS queries to malicious domains.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Web Filter profile
Why it's wrong here
Web Filter profile operates at the HTTP/HTTPS layer, inspecting URL categories, host headers, and SNI from actual web requests. DNS queries are UDP/TCP port 53 datagrams sent before any HTTP communication, and they carry only the domain name and record type—not a full URL or Host header. Because FortiGate's Web Filter does not evaluate DNS query payloads, it cannot block or allow a domain at the resolution stage, so it is unsuitable for DNS-based blocking.
- ✗
IPS profile
Why it's wrong here
IPS profile uses signature and anomaly detection to identify malicious traffic, and it can recognize some DNS-based attacks like tunneling, cache poisoning, or NXDOMAIN floods. However, IPS is not a policy-driven category filter: it cannot block a domain simply because it falls under categories such as malware, adult content, or phishing unless a specific attack signature is matched. Ordinary DNS queries to a blocked category look benign to IPS, so it is not designed for DNS category filtering.
- ✗
Application Control profile
Why it's wrong here
Application Control profile identifies applications by their unique protocol fingerprints, port usage, and behavioral signatures, and it can natively recognize the DNS protocol itself. But App Control does not parse the queried fully qualified domain name to enforce category-based allow/deny decisions; it can only block the entire DNS protocol or specific DNS-related applications, not individual domains. Therefore, using App Control for DNS blocking would be overly broad and not capable of granular domain policy.
- ✓
DNS Filter profile
Why this is correct
DNS Filter profile is purpose-built to inspect DNS query messages on port 53, comparing the queried domain against FortiGuard’s DNS category database and botnet indicators. It can take actions such as block, monitor, redirect, or allow based on domain category, and it supports sinkholing for botnet C2 domains. By operating below the web and application layers, DNS Filter can block malicious domains even for HTTPS, non-HTTP, or custom applications, making it the correct choice for DNS-level blocking.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.