Courseiva
Security Profiles →easyMultiple Choice

NSE4 Security Profiles Practice Question

Which web filtering feature allows an administrator to force web search engines to filter explicit content in search results, regardless of the user's browser settings?

⚠ Common exam trap

A common mix-up: candidates confuse DNS filter or URL filter with safe search, thinking that blocking explicit content at the domain or URL level is equivalent to filtering search results, but only safe search modifies the actual search engine query parameters to enforce content filtering at the source.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Safe search

Safe search is a web filtering feature that forces supported search engines (e.g., Google, Bing, Yahoo) to filter explicit content from search results by appending specific query parameters (such as `safe=active` for Google) to the search request. This enforcement occurs at the FortiGate proxy level, overriding the user's browser settings and ensuring compliance with acceptable use policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS filter

    Why it's wrong here

    DNS filtering resolves or blocks domain names, but SafeSearch enforcement requires rewriting the search request itself, which DNS cannot do. It is tempting because DNS filtering also restricts web content categorically, and it would be the correct choice for blocking access to named domains such as gambling or malware sites.

  • ✗

    URL filter

    Why it's wrong here

    A URL filter blocks or allows access to specific websites or URL patterns based on administrator-defined categories or lists, but it cannot modify the content returned by a search engine. The stem requires a feature that forces search engines to filter explicit results at the query level, which is achieved by enforcing Safe Search via a DNS-based or HTTPS inspection policy, not by URL filtering. This option is tempting because URL filters are commonly used to restrict access to adult websites, leading one to assume they also control search result content, but they operate on the destination address, not on the search query parameters.

  • ✗

    Application control

    Why it's wrong here

    Application control identifies and permits or blocks applications by signature, and cannot rewrite search-engine query parameters, so it cannot enforce SafeSearch. It is tempting because it also governs user activity on the web, and it would be the correct choice for blocking a specific application such as a proxy or peer-to-peer client.

  • ✓

    Safe search

    Why this is correct

    Safe search enforcement rewrites search-engine traffic so the engine itself filters explicit results, independent of browser preferences. This satisfies the requirement to force filtering regardless of user browser settings, since the FortiGate modifies the request rather than relying on client-side configuration.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.