nerdexam
FortinetFortinet

NSE4 · Question #6

NSE4 Question #6: Real Exam Question with Answer & Explanation

The correct answer is C: The FortiGate can scan web pages and email messages for instances of banned words.. FortiGate's banned word feature can scan web pages and email messages, allowing administrators to define these words using simple text, wildcards, or regular expressions for flexible content matching.

Submitted by eva_at· Apr 18, 2026Security Profiles and Content Inspection

Question

Which statements regarding banned words are correct? (Choose two.)

Options

  • AContent is automatically blocked if a single instance of a banned word appears.
  • BThe FortiGate updates banned words on a periodic basis.
  • CThe FortiGate can scan web pages and email messages for instances of banned words.
  • DBanned words can be expressed as simple text, wildcards and regular expressions.

Explanation

FortiGate's banned word feature can scan web pages and email messages, allowing administrators to define these words using simple text, wildcards, or regular expressions for flexible content matching.

Common mistakes.

  • A. The action taken when a banned word is detected (e.g., blocking) is configurable within DLP policies, often based on thresholds or policy settings, and is not automatically a block for every single instance.
  • B. Banned word lists are typically custom-defined by the administrator and are not automatically updated by FortiGuard on a periodic basis; FortiGuard provides updates for other security services like AV and web filtering categories.

Concept tested. FortiGate banned words configuration and scanning

Reference. https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/35763/data-leak-prevention-dlp

Topics

#Banned Words#Content Inspection#DLP#Pattern Matching

Community Discussion

No community discussion yet for this question.

Full NSE4 PracticeBrowse All NSE4 Questions