nerdexam
FortinetFortinet

NSE4 · Question #515

NSE4 Question #515: Real Exam Question with Answer & Explanation

The correct answer is A: Proxy based. Both proxy-based and flow-based web filtering modes on FortiGate are capable of inspecting the full URL for policy enforcement.

Submitted by ashley.k· Apr 18, 2026Security Profiles and Content Inspection

Question

Which of the following web filtering modes can inspect the full URL? (Choose two.)

Options

  • AProxy based
  • BDNS based
  • CPolicy based
  • DFlow based

Explanation

Both proxy-based and flow-based web filtering modes on FortiGate are capable of inspecting the full URL for policy enforcement.

Common mistakes.

  • B. DNS-based web filtering only inspects the domain name resolved through DNS queries and cannot see or filter based on the full URL path or query parameters.
  • C. Policy-based refers to the method of applying rules, not a specific inspection engine; web filtering policies themselves utilize either proxy-based or flow-based inspection modes.

Concept tested. FortiGate web filtering URL inspection

Reference. https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/337190/proxy-and-flow-based-inspection

Topics

#Web Filtering#Inspection Modes#Proxy Inspection#Flow Inspection

Community Discussion

No community discussion yet for this question.

Full NSE4 PracticeBrowse All NSE4 Questions