Courseiva

NSE4 High Availability and Diagnostics Practice Question

A FortiGate admin wants to inspect SSL-encrypted traffic for threats using IPS. The admin creates an SSL inspection profile with 'full SSL inspection' and applies it to the policy. What additional configuration is necessary for the IPS engine to process the decrypted traffic?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply an IPS sensor to the same firewall policy

IPS inspection requires that the security profile (IPS sensor) is also applied to the same firewall policy. SSL inspection alone only decrypts; the IPS profile inspects the decrypted traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable 'set ssl-ssh-profile' under the IPS sensor

    Why it's wrong here

    The `set ssl-ssh-profile` command is valid under a firewall policy or a profile group, not under an IPS sensor. An IPS sensor is designed to hold IPS signatures, filters, and protocol options; it has no decryption-profile parameter. Attempting to bind an SSL/SSH inspection profile inside an IPS sensor is a configuration error in FortiGate's CLI and reflects a misunderstanding of where decryption and IPS enforcement are configured.

  • ✗

    Enable 'IPS' under the SSL inspection profile

    Why it's wrong here

    The SSL/SSH inspection profile's sole job is to determine decryption behavior: which sessions to deep-inspect, which to exempt, and whether to use certificate inspection or full proxy-based decryption. It does not include an 'IPS' toggle because IPS enforcement is delivered through a separate security profile object. Even if a setting named 'IPS' existed within the SSL profile, no security scanning would occur without an IPS sensor explicitly attached to the firewall policy.

  • ✗

    Configure the FortiGate's CA certificate on clients

    Why it's wrong here

    Trusting the FortiGate CA certificate on client machines is a necessary prerequisite for deep SSL inspection, but it does not perform any intrusion prevention function. This step only teaches clients to accept the FortiGate-generated certificate during the TLS handshake. Configuring CA trust will never create an IPS sensor or cause IPS signatures to be evaluated; without an IPS sensor bound to the policy, decrypted traffic is not scanned for exploits.

  • ✓

    Apply an IPS sensor to the same firewall policy

    Why this is correct

    An IPS sensor must be explicitly applied to the same firewall policy that references the SSL/SSH inspection profile. After the SSL/SSH proxy decrypted the traffic, the flow or proxy engine passes the decrypted payload to the IPS sensor, which matches it against configured intrusion signatures and enforces the defined action. Policy-level binding is essential: without both the SSL/SSH profile and the IPS sensor on the same policy, the FortiGate cannot inspect the decrypted content for threats.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.