Courseiva
Security Profiles →easyMultiple Choice

NSE4 Security Profiles Practice Question

Which FortiGate security profile is BEST suited for blocking DNS queries to known malicious domains?

⚠ Common exam trap

NSE4 often tests the layer confusion between Web Filter (HTTP/HTTPS) and DNS Filter (DNS), so candidates pick Web Filter thinking it covers all domain-based blocking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS Filter profile

The DNS Filter profile on FortiGate is purpose-built to inspect DNS queries and block resolution of known malicious domains by comparing them against FortiGuard DNS threat intelligence. It operates at the DNS layer, so it stops the connection before it is even established. This is the most direct and efficient control for blocking DNS queries to malicious domains.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Web Filter profile

    Why it's wrong here

    Web Filter profile operates at the HTTP/HTTPS layer, inspecting URL categories, host headers, and SNI from actual web requests. DNS queries are UDP/TCP port 53 datagrams sent before any HTTP communication, and they carry only the domain name and record type—not a full URL or Host header. Because FortiGate's Web Filter does not evaluate DNS query payloads, it cannot block or allow a domain at the resolution stage, so it is unsuitable for DNS-based blocking.

  • ✗

    IPS profile

    Why it's wrong here

    IPS profile uses signature and anomaly detection to identify malicious traffic, and it can recognize some DNS-based attacks like tunneling, cache poisoning, or NXDOMAIN floods. However, IPS is not a policy-driven category filter: it cannot block a domain simply because it falls under categories such as malware, adult content, or phishing unless a specific attack signature is matched. Ordinary DNS queries to a blocked category look benign to IPS, so it is not designed for DNS category filtering.

  • ✗

    Application Control profile

    Why it's wrong here

    Application Control profile identifies applications by their unique protocol fingerprints, port usage, and behavioral signatures, and it can natively recognize the DNS protocol itself. But App Control does not parse the queried fully qualified domain name to enforce category-based allow/deny decisions; it can only block the entire DNS protocol or specific DNS-related applications, not individual domains. Therefore, using App Control for DNS blocking would be overly broad and not capable of granular domain policy.

  • ✓

    DNS Filter profile

    Why this is correct

    DNS Filter profile is purpose-built to inspect DNS query messages on port 53, comparing the queried domain against FortiGuard’s DNS category database and botnet indicators. It can take actions such as block, monitor, redirect, or allow based on domain category, and it supports sinkholing for botnet C2 domains. By operating below the web and application layers, DNS Filter can block malicious domains even for HTTPS, non-HTTP, or custom applications, making it the correct choice for DNS-level blocking.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.