nerdexam
Fortinet

NSE4 · Question #236

A DLP rule with an action of Exempt has been matched against traffic passing through the FortiGate unit. Which of the following statements is correct regarding how this transaction will be handled by

The correct answer is A. Any other matched DLP rules will be ignored with the exception of Archiving.. When a DLP rule with an 'Exempt' action is matched, subsequent DLP rules are ignored for that transaction, allowing the traffic to pass, but archiving actions might still proceed.

Submitted by the_admin· Apr 18, 2026Security Profiles and Content Inspection

Question

A DLP rule with an action of Exempt has been matched against traffic passing through the FortiGate unit. Which of the following statements is correct regarding how this transaction will be handled by the FortiGate unit?

Options

  • AAny other matched DLP rules will be ignored with the exception of Archiving.
  • BFuture files whose characteristics match this file will bypass DLP scanning.
  • CThe traffic matching the DLP rule will bypass antivirus scanning.
  • DThe client IP address will be added to a white list.

How the community answered

(19 responses)
  • A
    89% (17)
  • B
    5% (1)
  • D
    5% (1)

Why each option

When a DLP rule with an 'Exempt' action is matched, subsequent DLP rules are ignored for that transaction, allowing the traffic to pass, but archiving actions might still proceed.

AAny other matched DLP rules will be ignored with the exception of Archiving.Correct

When a DLP rule with an 'Exempt' action matches traffic, the FortiGate will cease evaluating subsequent DLP rules for that specific traffic flow within the same DLP profile, effectively letting the traffic pass from a DLP perspective, but the 'Archive' action is an auditing function that can still be performed.

BFuture files whose characteristics match this file will bypass DLP scanning.

The 'Exempt' action applies only to the current matching transaction and does not create a persistent bypass for future files based on their characteristics.

CThe traffic matching the DLP rule will bypass antivirus scanning.

The DLP 'Exempt' action only impacts DLP processing and does not inherently cause the traffic to bypass other UTM features like Antivirus scanning.

DThe client IP address will be added to a white list.

The 'Exempt' action does not automatically add client IP addresses to a whitelist; whitelisting is a separate configuration.

Concept tested: FortiGate DLP actions, specifically 'Exempt'

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/526786/data-leak-prevention

Topics

#DLP#FortiGate DLP#Security Profiles#Rule Actions

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice