nerdexam
Fortinet

NSE4 · Question #515

Which of the following web filtering modes can inspect the full URL? (Choose two.)

The correct answer is A. Proxy based D. Flow based. Both proxy-based and flow-based web filtering modes on FortiGate are capable of inspecting the full URL for policy enforcement.

Submitted by ashley.k· Apr 18, 2026Security Profiles and Content Inspection

Question

Which of the following web filtering modes can inspect the full URL? (Choose two.)

Options

  • AProxy based
  • BDNS based
  • CPolicy based
  • DFlow based

How the community answered

(31 responses)
  • A
    87% (27)
  • B
    10% (3)
  • C
    3% (1)

Why each option

Both proxy-based and flow-based web filtering modes on FortiGate are capable of inspecting the full URL for policy enforcement.

AProxy basedCorrect

Proxy-based web filtering operates as a full proxy, terminating connections and parsing the entire HTTP/HTTPS request, which includes complete URL inspection for deep policy application.

BDNS based

DNS-based web filtering only inspects the domain name resolved through DNS queries and cannot see or filter based on the full URL path or query parameters.

CPolicy based

Policy-based refers to the method of applying rules, not a specific inspection engine; web filtering policies themselves utilize either proxy-based or flow-based inspection modes.

DFlow basedCorrect

Flow-based inspection, while more lightweight than proxy-based, still performs application-layer inspection to process and filter traffic, enabling it to inspect the full URL of web requests.

Concept tested: FortiGate web filtering URL inspection

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/337190/proxy-and-flow-based-inspection

Topics

#Web Filtering#Inspection Modes#Proxy Inspection#Flow Inspection

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice