nerdexam
Fortinet

NSE4 · Question #307

Which statements about DNS filter profiles are true? (Choose two.)

The correct answer is C. They can block DNS request to known botnet command and control servers. D. They can redirect blocked requests to a specific portal. DNS filter profiles on FortiGate operate at the DNS protocol layer, inspecting DNS queries and responses. They can block DNS requests to known botnet command-and-control (C&C) server domains using FortiGuard's botnet domain database (C is correct). They can also redirect…

Submitted by renata2k· Apr 18, 2026Security Profiles and Content Inspection

Question

Which statements about DNS filter profiles are true? (Choose two.)

Options

  • AThey can inspect HTTP traffic.
  • BThey must be applied in firewall policies with SSL inspection enabled.
  • CThey can block DNS request to known botnet command and control servers.
  • DThey can redirect blocked requests to a specific portal.

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    92% (23)

Explanation

DNS filter profiles on FortiGate operate at the DNS protocol layer, inspecting DNS queries and responses. They can block DNS requests to known botnet command-and-control (C&C) server domains using FortiGuard's botnet domain database (C is correct). They can also redirect blocked DNS requests to a customizable block portal/IP instead of simply dropping them (D is correct). DNS filter profiles do not inspect HTTP traffic (A is incorrect) - that is the role of web filtering profiles. DNS filter profiles also do not require SSL inspection (B is incorrect) because standard DNS queries are sent in plaintext over UDP/TCP port 53; SSL inspection is relevant for HTTPS traffic inspection, not DNS.

Topics

#DNS Filtering#Security Profiles#Threat Protection#Blocked Request Redirection

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice