NSE4 Security Profiles Practice Question
A company uses deep SSL inspection to filter traffic. Users report that some HTTPS sites are not loading. The administrator checks the FortiGate and sees that the certificate for the sites is not trusted on the client machines. What is the most likely cause?
⚠ Common exam trap
Many candidates confuse the FortiGate's self-signed certificate used for its own web interface with the CA certificate required for deep inspection, or assume that 'no-inspection' would cause loading failures rather than bypassing inspection entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The FortiGate's CA certificate is not installed in the Trusted Root Certification Authorities store on the clients.
When deep SSL inspection is enabled, the FortiGate acts as a man-in-the-middle by decrypting HTTPS traffic using a local CA certificate. For clients to trust the decrypted connections, the FortiGate's CA certificate must be installed in the Trusted Root Certification Authorities store on each client machine. If it is missing, the browser will display a certificate trust error and may block the site, causing the reported loading failures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The FortiGate's CA certificate is not installed in the Trusted Root Certification Authorities store on the clients.
Why this is correct
The FortiGate's CA certificate is not installed in the Trusted Root Certification Authorities store on the clients. Deep SSL inspection works by having the FortiGate intercept TLS traffic and present a real-time generated certificate signed by a FortiGate-owned CA. If that CA is not present in the client's trusted root store, the browser cannot verify the chain of trust and will display a certificate error or block the connection entirely. Installing the FortiGate CA in the Trusted Root Certification Authorities store on all clients is a mandatory prerequisite for seamless deep inspection.
- ✗
The FortiGate is using a self-signed certificate for the SSL inspection policy.
Why it's wrong here
The FortiGate is using a self-signed certificate for the SSL inspection policy. This is incorrect reasoning because all FortiGate SSL inspection certificates are inherently self-signed from a CA perspective; the FortiGate's local CA issues them. The real problem is not that the certificate is self-signed, but that the client does not trust that CA. If the FortiGate's self-signed CA were distributed to clients as a trusted root, the browser would accept the inspection certificates without issue. Thus, focusing on the certificate being self-signed misses the actual trust-root problem.
- ✗
The SSL inspection policy is set to 'no-inspection' for the affected sites.
Why it's wrong here
The SSL inspection policy is set to 'no-inspection' for the affected sites. If 'no-inspection' is configured, the FortiGate would simply pass the TLS traffic through without intercepting it, so no inspection certificate would be presented to the client. In that scenario, the browser would see the original valid certificate from the destination site and would not raise any certificate warnings. The user is reporting certificate errors, which indicates that inspection is happening, so this is not a valid cause.
- ✗
The FortiGate's web filter profile is blocking the certificate.
Why it's wrong here
The FortiGate's web filter profile is blocking the certificate. Web filter profiles in FortiOS operate at the application or URL level, not on certificates; they can block or allow based on categories, URLs, and content but cannot block a specific certificate. Certificate errors during deep inspection are generated by the TLS handshake because the browser distrusts the presented certificate, not by a web filter action. The web filter never sees the certificate itself; it only controls which sites or content are permitted after the TLS session is established.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.