NSE4 Security Profiles Practice Question
Which TWO of the following are best practices when configuring IPS on a FortiGate in a high-throughput environment?
⚠ Common exam trap
It's easy for candidates to assume 'maximum security' means enabling all signatures or using the strictest action, but the NSE4 exam emphasizes that effective IPS in high-throughput environments requires balancing security with performance by selectively enabling relevant signatures and using flow-based inspection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable only relevant signatures based on the network environment.
Enabling only relevant signatures based on the network environment reduces false positives and unnecessary processing overhead, ensuring that IPS resources are focused on threats that actually apply to the traffic traversing the FortiGate. Option E is correct because flow-based inspection uses a single-pass, pattern-matching engine that offers higher throughput and lower latency compared to proxy-based inspection, making it ideal for high-throughput environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set all signatures to block action to maximize security.
Why it's wrong here
Setting every signature to block action is dangerous because it indiscriminately drops traffic that often matches low-confidence or informational patterns, causing false positives that disrupt legitimate business operations. It also creates excessive CPU and memory load on the FortiGate, as every flow is matched against the full signature set. Modern IPS best practice is to align action with asset criticality and chosen inspection mode, leaving high-impact 'critical' signatures to block while defaulting others to monitor so you can tune with evidence.
- ✗
Set the IPS severity filter to high and above only.
Why it's wrong here
Filtering to high and above only would blind you to the full attack chain, since many exploits begin with medium-severity scanner probes or logic flaws that later escalate to remote code execution. Many zero-day and targeted attacks are intentionally crafted to evade severity scoring, and a single medium event on a domain controller can outweigh a high event on a low-value host. The severity filter should be combined with the risk-based prioritization that accounts for asset value and attack relevance, not used as the sole trigger.
- ✗
Disable all custom signatures to simplify management.
Why it's wrong here
Disabling all custom signatures removes the ability to detect environment-specific threats that vendors cannot ship as prebuilt rules, such as internal tool misuse, regional malware, or newly emerging CVEs for software unique to your deployment. While reducing rule count can simplify management, it also strips away the core value proposition of an IPS: tailored detection. You should instead review and validate custom signatures in simulation mode before enabling them, maintaining them as a small but actively maintained set.
- ✓
Enable only relevant signatures based on the network environment.
Why this is correct
Enabling only signatures that matter to your deployed OS, applications, and services is the central best practice because it dramatically reduces false positive noise and the performance overhead of matching irrelevant rules. FortiGate allows you to create IPS policies that reference specific rule sets, and you can also use the 'Network Inspection' view to quickly see which signatures match your actual traffic. This approach keeps detection fidelity high and aligns with the recommendation to never run a blanket signature set.
- ✓
Use flow-based inspection for better performance.
Why this is correct
Flow-based inspection is a correct best practice for high-throughput FortiGate deployments because it inspects traffic in a single pass using the receive path, leveraging NP-accelerated hardware and avoiding the larger latency and CPU costs of proxy-based inspection. It is specifically recommended by Fortinet for environments that demand tens of Gbps throughput, where proxy-based inspection would become a bottleneck. The trade-off is that flow-based does not offer the same deep, anti-evasion reconstruction as proxy-based, so you would pair it with well-tuned signature selection to retain critical visibility.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.