nerdexam
Fortinet

NSE4 · Question #11

Which two web filtering inspection modes inspect the full URL? (Choose two.)

The correct answer is B. Proxy-based. C. Flow-based. Proxy-based and Flow-based web filtering inspection modes both allow for the inspection of the full URL in HTTP/HTTPS traffic.

Submitted by viktor_hu· Apr 18, 2026Security Profiles and Content Inspection

Question

Which two web filtering inspection modes inspect the full URL? (Choose two.)

Options

  • ADNS-based.
  • BProxy-based.
  • CFlow-based.
  • DURL-based.

How the community answered

(51 responses)
  • A
    10% (5)
  • B
    86% (44)
  • D
    4% (2)

Why each option

Proxy-based and Flow-based web filtering inspection modes both allow for the inspection of the full URL in HTTP/HTTPS traffic.

ADNS-based.

DNS-based web filtering inspects only DNS queries, not the full HTTP/HTTPS URL. It blocks access to malicious domains before the connection is established based on the domain name resolved.

BProxy-based.Correct

Proxy-based web filtering operates at the application layer, acting as an intermediary to fully inspect HTTP/HTTPS traffic, including the entire URL, before forwarding it to the client. This deep inspection allows for detailed URL pattern matching and category enforcement.

CFlow-based.Correct

Flow-based web filtering inspects traffic as it passes through the FortiGate, but it can still perform deep packet inspection for web traffic (HTTP/HTTPS) to analyze the full URL and apply web filtering policies. While not a full proxy, it is capable of full URL inspection for standard web protocols.

DURL-based.

URL-based is not a standard inspection mode in the context of FortiGate web filtering; rather, it describes the object or criteria being filtered, which can be applied within proxy or flow modes.

Concept tested: FortiGate web filtering inspection modes and URL inspection

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/522100/web-filtering-inspection-modes

Topics

#Web Filtering#Inspection Modes#Full URL Inspection#Security Profiles

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice