NSE7 Advanced Threat Protection Practice Question
A FortiGate administrator is using the built-in FortiGuard web filter to block malicious websites. Users report that they can still access a site that is categorized as 'Malware' by FortiGuard. The administrator verifies that the web filter profile is applied to the policy and that the category is set to block. What is the most likely reason for this issue?
⚠ Common exam trap
The trap here is assuming that web filtering works on HTTPS without SSL inspection, overlooking the need to decrypt traffic to see the full URL and apply categories.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The site is using HTTPS and SSL inspection is not enabled.
The most likely reason is that the site uses HTTPS and SSL inspection is not enabled. FortiGate cannot inspect the encrypted traffic to determine the URL category, so the web filter cannot block it. Enabling SSL inspection allows FortiGate to decrypt and apply the web filter. Other options like cache, monitor mode, or FortiGuard reachability are less likely given the scenario details. Thus, SSL inspection is the key.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The web filter profile is set to monitor mode instead of block.
Why it's wrong here
The administrator already verified that the category is set to block, so the profile is not in monitor mode for that category. If it were monitor mode, the site would be allowed but logged. Since the administrator checked, this is not the issue. However, it's a good practice to double-check the entire profile, but given the scenario, this is less likely than SSL inspection.
- ✓
The site is using HTTPS and SSL inspection is not enabled.
Why this is correct
Without SSL inspection, FortiGate cannot see the full URL or the server certificate details for HTTPS traffic, so it cannot apply web filtering based on the category of the site. The web filter may see only the IP address or SNI, which might not be categorized. Enabling SSL inspection allows FortiGate to decrypt and inspect the traffic, enforcing the web filter. This is the most common reason for web filter bypass on HTTPS sites.
- ✗
The FortiGuard service is not reachable.
Why it's wrong here
If FortiGuard is unreachable, FortiGate may use a cached rating or fail open depending on configuration. However, the administrator sees that the site is categorized as Malware, implying that FortiGuard ratings are available. If the service were unreachable, other categories might also fail. This is not the most likely reason for a specific site bypass, especially if other sites are blocked correctly.
- ✗
The web filter cache has not been updated.
Why it's wrong here
The web filter cache stores recently accessed URLs and their categories. If the cache is stale, it might have an outdated category, but FortiGuard updates are frequent. However, if the site is already categorized as Malware by FortiGuard, the cache would eventually reflect that. A stale cache is possible but less likely than other causes, and the administrator can clear the cache. This is not the most probable reason.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.