nerdexam
Fortinet

NSE4 · Question #280

Which of the following statements is correct about configuring web filtering overrides?

The correct answer is C. The Override Scopes of User and User Group are only for use when Firewall Policy. Web filtering overrides with a scope of 'User' or 'User Group' require Firewall Policy Authentication to identify the individual user or group for proper application.

Submitted by suresh_in· Apr 18, 2026Security Profiles and Content Inspection

Question

Which of the following statements is correct about configuring web filtering overrides?

Options

  • AThe Override option for FortiGuard Web Filtering is available for any user group type.
  • BAdmin overrides require an administrator to manually allow pending override requests which are
  • CThe Override Scopes of User and User Group are only for use when Firewall Policy
  • DUsing Web Filtering Overrides requires the use of Firewall Policy Authentication.

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    95% (36)

Why each option

Web filtering overrides with a scope of 'User' or 'User Group' require Firewall Policy Authentication to identify the individual user or group for proper application.

AThe Override option for FortiGuard Web Filtering is available for any user group type.

The Override option for FortiGuard Web Filtering is not available for 'any' user group type; it typically requires authenticated users or specific user group definitions.

BAdmin overrides require an administrator to manually allow pending override requests which are

While some systems might involve manual approval, FortiGate web filtering overrides can be configured for direct application without a pending request requiring an administrator to manually allow each one.

CThe Override Scopes of User and User Group are only for use when Firewall PolicyCorrect

When web filtering overrides are configured to apply to specific users or user groups, the FortiGate unit must first identify who the user is. This user identification is accomplished through Firewall Policy Authentication, which authenticates the user and associates them with their respective group, allowing the specific override rules to be enforced.

DUsing Web Filtering Overrides requires the use of Firewall Policy Authentication.

While Firewall Policy Authentication is crucial for User/User Group scoped overrides, it's not strictly required for *all* web filtering overrides; for example, a simple URL pattern override can be applied globally without user authentication.

Concept tested: FortiGate Web Filtering Overrides and authentication requirements

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/501728/web-filter-overrides

Topics

#Web Filtering#Overrides#Authentication#Firewall Policies

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice