NSE4 · Question #515
Which of the following web filtering modes can inspect the full URL? (Choose two.)
The correct answer is A. Proxy based D. Flow based. Both proxy-based and flow-based web filtering modes on FortiGate are capable of inspecting the full URL for policy enforcement.
Question
Which of the following web filtering modes can inspect the full URL? (Choose two.)
Options
- AProxy based
- BDNS based
- CPolicy based
- DFlow based
How the community answered
(31 responses)- A87% (27)
- B10% (3)
- C3% (1)
Why each option
Both proxy-based and flow-based web filtering modes on FortiGate are capable of inspecting the full URL for policy enforcement.
Proxy-based web filtering operates as a full proxy, terminating connections and parsing the entire HTTP/HTTPS request, which includes complete URL inspection for deep policy application.
DNS-based web filtering only inspects the domain name resolved through DNS queries and cannot see or filter based on the full URL path or query parameters.
Policy-based refers to the method of applying rules, not a specific inspection engine; web filtering policies themselves utilize either proxy-based or flow-based inspection modes.
Flow-based inspection, while more lightweight than proxy-based, still performs application-layer inspection to process and filter traffic, enabling it to inspect the full URL of web requests.
Concept tested: FortiGate web filtering URL inspection
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/337190/proxy-and-flow-based-inspection
Topics
Community Discussion
No community discussion yet for this question.