nerdexam
Fortinet

NSE4 · Question #172

Users may require access to a web site that is blocked by a policy. Administrators can give users the ability to override the block. Which of the following statements regarding overrides is NOT…

The correct answer is A. A web filter profile may only have one user group defined as an override group. The incorrect statement regarding web filtering overrides is that a web filter profile can only define one user group for override privileges, as multiple groups are supported.

Submitted by hans_de· Apr 18, 2026Security Profiles and Content Inspection

Question

Users may require access to a web site that is blocked by a policy. Administrators can give users the ability to override the block. Which of the following statements regarding overrides is NOT correct?

Options

  • AA web filter profile may only have one user group defined as an override group.
  • BA firewall user group can be used to provide override privileges for FortiGuard Web Filtering.
  • CWhen requesting an override, the matched user must belong to a user group for which the
  • DOverrides can be allowed by the administrator for a specific period of time.

How the community answered

(46 responses)
  • A
    89% (41)
  • B
    7% (3)
  • C
    2% (1)
  • D
    2% (1)

Why each option

The incorrect statement regarding web filtering overrides is that a web filter profile can only define one user group for override privileges, as multiple groups are supported.

AA web filter profile may only have one user group defined as an override group.Correct

A web filter profile can be configured to allow multiple user groups to perform overrides, not restrictively only one user group.

BA firewall user group can be used to provide override privileges for FortiGuard Web Filtering.

Firewall user groups are indeed used to grant override privileges for FortiGuard Web Filtering, allowing specific groups to bypass blocks.

CWhen requesting an override, the matched user must belong to a user group for which the

For an override to be successful, the user requesting it must authenticate and belong to a user group specifically configured with override permissions.

DOverrides can be allowed by the administrator for a specific period of time.

FortiGate allows administrators to specify a duration or time limit for web filter overrides, after which they automatically expire.

Concept tested: FortiGate web filter override limitations

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/526786/web-filter-overrides

Topics

#Web Filtering#FortiGuard#Overrides#User Groups

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice