Courseiva
Security Profiles →mediumMultiple Select

NSE4 Security Profiles Practice Question

A FortiGate administrator is configuring IPS to protect against a known exploit targeting a web server. The administrator wants to ensure that the IPS engine can decode the HTTP protocol. Which TWO actions are necessary?

⚠ Common exam trap

Candidates often confuse the IPS action (block, monitor) with the enabling of protocol decoders, or assume SSL deep inspection alone is sufficient for HTTP inspection, when in fact both the HTTP decoder and SSL deep inspection are required for encrypted web traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the HTTP protocol decoder in the IPS sensor

The HTTP protocol decoder must be enabled in the IPS sensor because the IPS engine uses protocol decoders to normalize traffic and apply signatures correctly. Without the HTTP decoder, the IPS engine cannot parse HTTP headers, methods, or URIs, making it blind to web-based exploits. This is a prerequisite for any HTTP-specific IPS inspection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable the HTTP protocol decoder in the IPS sensor

    Why this is correct

    The IPS engine uses protocol decoders to parse and normalize traffic into a structured format for signature matching. Without the HTTP decoder, the engine processes raw TCP segments and cannot interpret HTTP headers, URLs, or payloads, so HTTP-specific signatures won't trigger correctly. Enabling this decoder is mandatory for any meaningful HTTP inspection.

  • ✗

    Configure an IP pool for the web server

    Why it's wrong here

    An IP pool is a NAT construct used for source address translation when traffic egresses the FortiGate, not a mechanism that influences intrusion prevention. IPS inspection occurs independently of NAT decisions; the sensor inspects the translated or un-translated packet content. Configuring an IP pool for the web server would not activate the HTTP decoder or enable inspection of HTTP traffic.

  • ✓

    Enable SSL deep inspection on the firewall policy

    Why this is correct

    If the web traffic is HTTPS, the payload is encrypted, so the IPS engine cannot parse HTTP headers or signatures directly without decrypted content. Enabling SSL deep inspection on the firewall policy allows the FortiGate to intercept, decrypt, and feed plaintext to the IPS HTTP decoder for analysis. This is essential for HTTP/HTTPS inspection, but it assumes the HTTP decoder is already enabled in the sensor; it's complementary, not a substitute.

  • ✗

    Set the IPS action to 'block'

    Why it's wrong here

    The IPS action parameter—such as 'block', 'monitor', or 'reset'—determines how the FortiGate responds once a signature has already matched. It has no effect on whether the HTTP protocol decoder is enabled; without the decoder, the engine cannot generate a match against HTTP-based attacks in the first place. So setting the action to 'block' does not solve the underlying parsing issue.

  • ✗

    Disable the FTP protocol decoder

    Why it's wrong here

    The FTP protocol decoder is a separate component that parses File Transfer Protocol commands and data channels; disabling it would only reduce FTP inspection capabilities. It operates independently of the HTTP decoder, and the presence of FTP typically coexists with HTTP on the same sensor without interference. No requirement exists to disable unrelated decoders to get HTTP inspection working, so this action is both unnecessary and potentially harmful.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.