nerdexam
Fortinet

NSE4 · Question #209

Each UTM feature has configurable UTM objects such as sensors, profiles or lists that define how the feature will function. An administrator must assign a set of UTM features to a group of users…

The correct answer is B. The administrator must enable the UTM features in an identify-based policy applicable to the user. This question asks how to assign Unified Threat Management (UTM) features to a group of users on a FortiGate.

Submitted by jakub_pl· Apr 18, 2026Firewall Policies and Authentication

Question

Each UTM feature has configurable UTM objects such as sensors, profiles or lists that define how the feature will function. An administrator must assign a set of UTM features to a group of users. Which of the following is the correct method for doing this?

Options

  • AEnable a set of unique UTM features under "Edit User Group".
  • BThe administrator must enable the UTM features in an identify-based policy applicable to the user
  • CWhen defining the UTM objects, the administrator must list the user groups which will use the
  • DThe administrator must apply the UTM features directly to a user object.

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    86% (24)
  • C
    4% (1)
  • D
    4% (1)

Why each option

This question asks how to assign Unified Threat Management (UTM) features to a group of users on a FortiGate.

AEnable a set of unique UTM features under "Edit User Group".

UTM features are not enabled directly under "Edit User Group"; user groups are used in policies, and policies enable the UTM features.

BThe administrator must enable the UTM features in an identify-based policy applicable to the userCorrect

To apply UTM features to a group of users, the administrator must configure an identity-based firewall policy that matches the user group and then enable the desired UTM profiles (e.g., antivirus, web filter, IPS) within that specific policy. This ensures that traffic from those users is subjected to the defined security inspection.

CWhen defining the UTM objects, the administrator must list the user groups which will use the

While UTM objects are defined, they are applied *in a policy*, not by listing user groups within the object definition itself.

DThe administrator must apply the UTM features directly to a user object.

UTM features are applied to traffic *through* policies that match users or user groups, not directly to individual user objects.

Concept tested: Applying UTM features via identity-based policies

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/60829/applying-security-profiles

Topics

#UTM Features#Firewall Policies#User-based Policies#Security Profiles

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice