nerdexam
Fortinet

NSE4 · Question #428

Which of the following statements are true regarding the web filtering modes? (Choose two.)

The correct answer is A. Proxy based mode allows for customizable block pages to display when sites are prevented. B. Proxy based mode requires more resources than flow-based. This question tests the understanding of characteristics differentiating proxy-based and flow-based web filtering modes on FortiGate.

Submitted by noor.lb· Apr 18, 2026Security Profiles and Content Inspection

Question

Which of the following statements are true regarding the web filtering modes? (Choose two.)

Options

  • AProxy based mode allows for customizable block pages to display when sites are prevented.
  • BProxy based mode requires more resources than flow-based.
  • CFlow based mode offers more settings under the advanced configuration section of the GUI.
  • DProxy based mode offers higher throughput than flow-based mode.

How the community answered

(40 responses)
  • A
    85% (34)
  • C
    5% (2)
  • D
    10% (4)

Why each option

This question tests the understanding of characteristics differentiating proxy-based and flow-based web filtering modes on FortiGate.

AProxy based mode allows for customizable block pages to display when sites are prevented.Correct

Proxy-based web filtering inspects the full HTTP/HTTPS payload, which enables the FortiGate to display customizable block pages to users when access to a specific site is denied, enhancing user experience and providing policy context.

BProxy based mode requires more resources than flow-based.Correct

Proxy-based mode requires more CPU and memory resources than flow-based mode because it performs deep packet inspection, reassembles sessions, and acts as an intermediary, leading to higher processing overhead.

CFlow based mode offers more settings under the advanced configuration section of the GUI.

Proxy-based mode typically offers more advanced configuration settings for web filtering compared to flow-based mode, which is designed for performance with fewer granular controls.

DProxy based mode offers higher throughput than flow-based mode.

Proxy-based mode generally offers lower throughput than flow-based mode due to its extensive inspection processes and resource demands, while flow-based mode is optimized for speed by inspecting packets on the fly.

Concept tested: FortiGate web filtering modes comparison

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/483664/web-filter-introduction

Topics

#Web Filtering#Proxy Mode#Flow Mode#Security Profiles

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice