NSE4 Security Profiles Practice Question
Which security profile is used to detect and prevent network-based attacks by analyzing traffic patterns and comparing them against known attack signatures?
⚠ Common exam trap
It's easy for candidates to confuse the IPS profile with the Antivirus profile, mistakenly thinking that antivirus handles all signature-based detection, but antivirus only scans files for malware, not network traffic patterns for attack signatures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IPS profile
The Intrusion Prevention System (IPS) profile is specifically designed to detect and prevent network-based attacks by inspecting traffic patterns and comparing them against a database of known attack signatures. Unlike other security profiles that focus on content or application-layer threats, the IPS profile operates at the network and transport layers to identify malicious patterns such as exploit attempts, buffer overflows, and denial-of-service attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DLP profile
Why it's wrong here
DLP profiles are designed to identify and prevent the unauthorized transfer of sensitive information, such as credit card numbers, personal data, or proprietary content, across network channels. They enforce data-loss prevention using content matching and predefined sensitive-data types, not network attack signatures. Since they do not analyze packets for exploit patterns or malicious behavior, they are not used to detect and prevent network attacks.
- ✓
IPS profile
Why this is correct
The IPS security profile uses a continuously updated FortiGuard IPS signature database, protocol anomaly detection, and packet-level deep inspection to identify and block network attack attempts in real time. It covers known CVE exploits, SQL injection, cross-site scripting, and other malicious network traffic. As the dedicated intrusion prevention mechanism, it is the correct profile for detecting and preventing network attacks.
- ✗
Web filter profile
Why it's wrong here
Web filter profiles evaluate clients' outbound HTTP/HTTPS requests against a URL category or reputation database and can block access to malicious or non-compliant websites. While this can prevent a user from visiting a phishing or malware-hosting site, it does not inspect or block the underlying network exploit traffic. Thus web filtering is a URL access control tool, not a network attack detection and prevention profile.
- ✗
Antivirus profile
Why it's wrong here
Antivirus profiles in FortiGate scan files for known malware signatures and heuristics as they traverse the firewall, focusing specifically on payloads in email, web downloads, and file transfers. They do not inspect network protocol behavior, exploit attempts, or abnormal traffic patterns that characterize network-level attacks. Therefore, an antivirus profile alone cannot detect or prevent intrusion attempts against a host or service.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.