Courseiva
Security Profiles →hardMultiple Select

NSE4 Security Profiles Practice Question

Which TWO statements about IPS in FortiGate are true?

⚠ Common exam trap

Many exam-takers assume IPS requires routed mode or flow-based inspection only, but FortiGate supports IPS in transparent mode and in both inspection modes, and sensors are reusable across multiple policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IPS can be applied to individual firewall policies via IPS sensors.

IPS sensors are applied directly to individual firewall policies, allowing granular control over which traffic is inspected for intrusions. This enables administrators to enforce different IPS profiles for different traffic flows, such as applying a stricter sensor to internet-bound traffic and a lighter one to internal traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    IPS can be applied to individual firewall policies via IPS sensors.

    Why this is correct

    In FortiGate, IPS is enforced at the firewall policy level by assigning an IPS sensor to the policy's Security Profiles. This design lets each policy pass traffic through the sensor's configured signature rules, enabling selective inspection for different source/destination pairs. Because a sensor is a reusable object, the same sensor can be applied to any number of policies, and changes to the sensor immediately affect all policies referencing it.

  • ✗

    An IPS sensor can only be applied to one firewall policy.

    Why it's wrong here

    IPS sensors in FortiOS are configuration objects that can be shared across multiple firewall policies simultaneously, so a single sensor is by no means limited to one policy. This object-based reuse is a deliberate design choice to avoid redundant configuration and ensure consistent inspection across traffic flows. An administrator would typically create a few sensors (e.g., 'severity-high' or 'strict-protection') and attach them to numerous policies that need the same level of IPS coverage.

  • ✗

    IPS is not supported in transparent mode.

    Why it's wrong here

    FortiGate IPS does not depend on routing or NAT, so it operates identically in transparent (Layer 2) mode where the device is effectively a bump in the wire. In transparent mode, IPS still inspects every packet forwarded through the interface pair, applying the same sensors, filters, and signature actions as in routed mode. The only practical difference is that some IPS debug commands or network-layer features might be limited, but the inspection engine itself is fully supported.

  • ✗

    IPS only works in flow-based inspection mode.

    Why it's wrong here

    FortiOS supports IPS in both flow-based and proxy-based inspection modes, so the claim that it only works in flow mode is incorrect. Flow mode processes packets as they arrive, offering lower latency and better scalability, while proxy mode reassembles the full stream, enabling deeper application-level inspection and integration with other proxy-based security features like DLP. An IPS sensor can be referenced by policies running either mode, and signature matching is performed by the same underlying engine.

  • ✓

    IPS signatures can have their actions overridden in an IPS filter.

    Why this is correct

    An IPS filter provides a method to override the default action of a specific signature or signature group before the sensor evaluates traffic. For example, if a signature's default action is 'block' but a critical application causes false positives, you can create an IPS filter that changes that signature's action to 'monitor' for certain traffic. The filter is then referenced inside an IPS sensor, and its override takes precedence over the signature's built-in configuration, allowing precise control without modifying the signature itself.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.