NSE4 Security Profiles Practice Question
Which security profile component is specifically designed to prevent data exfiltration by inspecting outgoing traffic for sensitive data patterns?
⚠ Common exam trap
A common mix-up: candidates confuse DLP with Web Filter or Application Control, thinking that blocking web categories or applications inherently prevents data exfiltration, but only DLP inspects the actual content of outgoing traffic for sensitive data patterns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Leak Prevention (DLP)
Data Leak Prevention (DLP) is the security profile component specifically designed to inspect outgoing traffic for sensitive data patterns, such as credit card numbers, social security numbers, or custom regex patterns. It uses deep packet inspection (DPI) to analyze content in emails, web uploads, and file transfers, blocking or alerting on matches to prevent unauthorized data exfiltration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Application Control
Why it's wrong here
Application Control is a NGFW security profile that identifies and categorizes network traffic by application (e.g., Facebook, SSH, or Salesforce) using signature matching, protocol decoding, and behavioral analysis. It enforces policies based on application identity and user context, but it does not inspect the payload for sensitive data patterns. Consequently, it can block traffic to a specific app but cannot detect whether that traffic contains credit card numbers, PII, or other confidential information.
- ✓
Data Leak Prevention (DLP)
Why this is correct
Data Leak Prevention (DLP) is the security profile specifically engineered to detect and prevent the unauthorized transmission of sensitive data. It uses deep content inspection techniques such as exact data matching, regex patterns, and file fingerprinting to identify regulated data elements like PCI-DSS card numbers, HIPAA-protected health records, and PII. DLP also considers contextual factors—source, destination, protocol, and direction—to enforce policies that block, quarantine, or log risky transmissions across SMTP, HTTP, FTP, and cloud apps.
- ✗
Antivirus
Why it's wrong here
Antivirus is a security profile that scans files and network traffic for known malware, viruses, and exploits using signature-based detection, heuristics, and sandboxing. Its primary function is to block malicious code before it reaches or leaves the host, not to analyze content for confidential data patterns. While antivirus does inspect data, it looks for harmful code signatures, not for sensitive information leakage, making it ineffective for DLP-type control.
- ✗
Web Filter
Why it's wrong here
Web Filter is a FortiGate security profile that controls access to URLs and websites based on category, reputation, keyword matching, and real-time threat intelligence. It acts at the domain or URL level, allowing or denying web access to enforce acceptable-use policies and block dangerous sites. Web Filter does not examine the content of uploaded or downloaded files for sensitive data, so it cannot detect or prevent a user from submitting a confidential document to a web form.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.