Courseiva
Advanced Threat Protection →mediumMultiple Choice

NSE7 Advanced Threat Protection Practice Question

A FortiGate administrator is using the built-in FortiGuard web filter to block malicious websites. Users report that they can still access a site that is categorized as 'Malware' by FortiGuard. The administrator verifies that the web filter profile is applied to the policy and that the category is set to block. What is the most likely reason for this issue?

⚠ Common exam trap

The trap here is assuming that web filtering works on HTTPS without SSL inspection, overlooking the need to decrypt traffic to see the full URL and apply categories.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The site is using HTTPS and SSL inspection is not enabled.

The most likely reason is that the site uses HTTPS and SSL inspection is not enabled. FortiGate cannot inspect the encrypted traffic to determine the URL category, so the web filter cannot block it. Enabling SSL inspection allows FortiGate to decrypt and apply the web filter. Other options like cache, monitor mode, or FortiGuard reachability are less likely given the scenario details. Thus, SSL inspection is the key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The web filter profile is set to monitor mode instead of block.

    Why it's wrong here

    The administrator already verified that the category is set to block, so the profile is not in monitor mode for that category. If it were monitor mode, the site would be allowed but logged. Since the administrator checked, this is not the issue. However, it's a good practice to double-check the entire profile, but given the scenario, this is less likely than SSL inspection.

  • ✓

    The site is using HTTPS and SSL inspection is not enabled.

    Why this is correct

    Without SSL inspection, FortiGate cannot see the full URL or the server certificate details for HTTPS traffic, so it cannot apply web filtering based on the category of the site. The web filter may see only the IP address or SNI, which might not be categorized. Enabling SSL inspection allows FortiGate to decrypt and inspect the traffic, enforcing the web filter. This is the most common reason for web filter bypass on HTTPS sites.

  • ✗

    The FortiGuard service is not reachable.

    Why it's wrong here

    If FortiGuard is unreachable, FortiGate may use a cached rating or fail open depending on configuration. However, the administrator sees that the site is categorized as Malware, implying that FortiGuard ratings are available. If the service were unreachable, other categories might also fail. This is not the most likely reason for a specific site bypass, especially if other sites are blocked correctly.

  • ✗

    The web filter cache has not been updated.

    Why it's wrong here

    The web filter cache stores recently accessed URLs and their categories. If the cache is stale, it might have an outdated category, but FortiGuard updates are frequent. However, if the site is already categorized as Malware by FortiGuard, the cache would eventually reflect that. A stale cache is possible but less likely than other causes, and the administrator can clear the cache. This is not the most probable reason.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.