Courseiva
Security Profiles →easyMultiple Choice

Troubleshooting: Application Control Not Blocking BitTorrent (Encrypted P2P)

A company wants to block all peer-to-peer file sharing applications on the network. Which FortiGate feature should be used to achieve this goal?

⚠ Common exam trap

A common mix-up: candidates confuse Application Control with IPS, assuming that IPS can block any unwanted traffic, but IPS focuses on threats and exploits, not on enforcing acceptable use policies for specific applications like P2P file sharing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Application Control

Application Control is the correct feature because it is specifically designed to identify and block peer-to-peer (P2P) file-sharing applications by inspecting traffic patterns and signatures, regardless of the port or protocol used. Unlike port-based blocking, Application Control uses deep packet inspection (DPI) to recognize P2P protocols such as BitTorrent, eDonkey, and Gnutella, even when they attempt to evade detection by using non-standard ports or encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Application Control

    Why this is correct

    Application Control is the correct security feature because it uses deep packet inspection and application signatures to identify P2P traffic regardless of port or protocol. It can block specific applications like BitTorrent, eMule, or LimeWire by matching their unique traffic patterns, even when they use non-standard ports or encryption. This is the only option that directly governs application usage rather than relying on ancillary factors such as URLs or hostnames.

  • ✗

    Web Filter

    Why it's wrong here

    A Web Filter evaluates HTTP and HTTPS requests against URL lists and content categories, such as 'Peer-to-Peer File Sharing' websites. However, P2P applications generate traffic over their own protocols—often on arbitrary ports or with peer-to-peer communication—that never goes through a web proxy. Even if the web filter blocks the download page for the P2P client, the actual file-sharing traffic continues unimpeded, making it ineffective for blocking the application itself.

  • ✗

    DNS Filter

    Why it's wrong here

    DNS Filtering intercepts DNS queries to block resolution of specific domains, but P2P clients are designed to be resilient and often use hard-coded IP addresses, trackers, or a list of peers instead of a single fixed domain. The application can function after a single DNS resolution, or bypass DNS entirely, so blocking the domain name does not stop the P2P data stream. It also cannot inspect payloads or identify application signatures, so it is unsuitable for application-aware blocking.

  • ✗

    Intrusion Prevention System (IPS)

    Why it's wrong here

    An Intrusion Prevention System is purpose-built to detect and prevent network attacks, such as exploit attempts, malware propagation, and vulnerability attacks, not to enforce policy on legitimate application usage. Although some IPS signatures may alert on P2P payloads to stop malicious content, this is incidental and leads to false positives or missed coverage when traffic is encrypted or uses legitimate protocols. Application Control is the correct feature for selectively blocking an entire application category, as it is designed for policy enforcement rather than threat prevention.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.