Courseiva
Security Profiles →hardMultiple Select

NSE4 Security Profiles Practice Question

Which THREE factors should be considered when tuning IPS to reduce false positives?

⚠ Common exam trap

Many candidates confuse performance optimization (hardware acceleration) with accuracy tuning, or mistakenly think that increasing sensitivity reduces false positives, when in fact it does the opposite.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Excluding trusted source IP addresses from certain signatures.

Excluding trusted source IP addresses from certain signatures prevents the IPS from generating alerts for traffic that is known to be legitimate, directly reducing false positives. This is a common tuning technique in FortiGate IPS where you can create exceptions for specific sources or destinations to avoid unnecessary alerts from benign traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Excluding trusted source IP addresses from certain signatures.

    Why this is correct

    By creating a source-IP exemption list for specific signatures, known-good hosts such as domain controllers or admin workstations are skipped during detection. This reduces false positives without weakening protection for untrusted endpoints, since traffic from other sources still hits the full signature set. This is a targeted, address-based tuning measure that preserves detection efficacy where it matters.

  • ✗

    Enabling hardware acceleration for IPS processing.

    Why it's wrong here

    Hardware acceleration offloads pattern matching to dedicated processors or the network processor unit, improving throughput and reducing latency under load. However, it does not alter the detection engine's classification logic or the signature parameters that determine a false positive. False positives are caused by traffic behavior and signature thresholds, not by the compute resources performing the inspection, so this is irrelevant to false-positive tuning.

  • ✗

    Increasing the sensitivity of signatures to catch more attacks.

    Why it's wrong here

    Raising sensitivity—such as lowering the threshold for anomaly detection or enabling stricter match flags—makes the IPS more permissive in what it flags as malicious. This inevitably increases the number of false positives because normal traffic variations are more likely to cross the lower bar. It is a coverage-vs-accuracy tradeoff and the opposite of a measure intended to reduce alert noise.

  • ✓

    Adjusting the severity threshold for which signatures generate alerts.

    Why this is correct

    Setting a minimum severity level, for example only alerting on High and Critical signatures, suppresses low-risk matches and drastically cuts down alert volume. This is a risk-based tuning approach that lets the IPS still detect all threats but only notify on those with operational significance. It does not alter detection itself, only the visibility of events that fall below the chosen threshold.

  • ✓

    Creating IPS filters to whitelist specific traffic patterns.

    Why this is correct

    IPS filters give granular control by allowing custom rules that match specific application-layer patterns, ports, or payload characteristics and apply an 'exclude' action. Unlike simple IP exemptions, these can whitelist benign traffic that looks suspicious but is known to be safe, such as protocol anomalies from a legitimate legacy application. This reduces false positives while keeping detection active for all other flows.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.