nerdexam
Fortinet

NSE4 · Question #210

Which of the following items represent the minimum configuration steps an administrator must perform to enable Data Leak Prevention for traffic flowing through the FortiGate unit? (Select all that…

The correct answer is A. Assign a DLP sensor in a firewall policy. D. Define one or more DLP rules. E. Define a DLP sensor. This question outlines the essential configuration steps required to enable and activate Data Leak Prevention (DLP) for network traffic on a FortiGate unit.

Submitted by tarun92· Apr 18, 2026Security Profiles and Content Inspection

Question

Which of the following items represent the minimum configuration steps an administrator must perform to enable Data Leak Prevention for traffic flowing through the FortiGate unit? (Select all that apply.)

Options

  • AAssign a DLP sensor in a firewall policy.
  • BApply one or more DLP rules to a firewall policy.
  • CEnable DLP globally using the config sys dlp command in the CLI.
  • DDefine one or more DLP rules.
  • EDefine a DLP sensor.
  • FApply a DLP sensor to a DoS sensor policy.

How the community answered

(25 responses)
  • A
    84% (21)
  • B
    8% (2)
  • C
    4% (1)
  • F
    4% (1)

Why each option

This question outlines the essential configuration steps required to enable and activate Data Leak Prevention (DLP) for network traffic on a FortiGate unit.

AAssign a DLP sensor in a firewall policy.Correct

After defining DLP rules and sensors, the DLP sensor must be assigned to a firewall policy to inspect the traffic passing through that policy for data leakage.

BApply one or more DLP rules to a firewall policy.

DLP rules are applied *to* a DLP sensor, and then the sensor is assigned to a policy; rules are not directly applied to a firewall policy independently of a sensor.

CEnable DLP globally using the config sys dlp command in the CLI.

DLP is enabled by configuring sensors and applying them to policies, not by a global CLI command `config sys dlp`.

DDefine one or more DLP rules.Correct

DLP functionality relies on specific rules that define what sensitive data to look for (e.g., credit card numbers, patterns), making rule definition a fundamental prerequisite.

EDefine a DLP sensor.Correct

DLP rules are grouped into a DLP sensor, which acts as a container for these rules and dictates actions upon a match, making its definition necessary before application.

FApply a DLP sensor to a DoS sensor policy.

A DLP sensor is applied to a *firewall policy* for data inspection, not to a DoS sensor policy, which serves a different security function.

Concept tested: FortiGate DLP configuration steps

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/469436/data-leak-prevention-dlp

Topics

#DLP#FortiGate Configuration#Security Profiles#Firewall Policies

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice