NSE4 Security Profiles Practice Question
A FortiGate administrator is configuring IPS to protect against a known exploit targeting a web server. The administrator wants to ensure that the IPS engine can decode the HTTP protocol. Which TWO actions are necessary?
⚠ Common exam trap
Candidates often confuse the IPS action (block, monitor) with the enabling of protocol decoders, or assume SSL deep inspection alone is sufficient for HTTP inspection, when in fact both the HTTP decoder and SSL deep inspection are required for encrypted web traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the HTTP protocol decoder in the IPS sensor
The HTTP protocol decoder must be enabled in the IPS sensor because the IPS engine uses protocol decoders to normalize traffic and apply signatures correctly. Without the HTTP decoder, the IPS engine cannot parse HTTP headers, methods, or URIs, making it blind to web-based exploits. This is a prerequisite for any HTTP-specific IPS inspection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable the HTTP protocol decoder in the IPS sensor
Why this is correct
The IPS engine uses protocol decoders to parse and normalize traffic into a structured format for signature matching. Without the HTTP decoder, the engine processes raw TCP segments and cannot interpret HTTP headers, URLs, or payloads, so HTTP-specific signatures won't trigger correctly. Enabling this decoder is mandatory for any meaningful HTTP inspection.
- ✗
Configure an IP pool for the web server
Why it's wrong here
An IP pool is a NAT construct used for source address translation when traffic egresses the FortiGate, not a mechanism that influences intrusion prevention. IPS inspection occurs independently of NAT decisions; the sensor inspects the translated or un-translated packet content. Configuring an IP pool for the web server would not activate the HTTP decoder or enable inspection of HTTP traffic.
- ✓
Enable SSL deep inspection on the firewall policy
Why this is correct
If the web traffic is HTTPS, the payload is encrypted, so the IPS engine cannot parse HTTP headers or signatures directly without decrypted content. Enabling SSL deep inspection on the firewall policy allows the FortiGate to intercept, decrypt, and feed plaintext to the IPS HTTP decoder for analysis. This is essential for HTTP/HTTPS inspection, but it assumes the HTTP decoder is already enabled in the sensor; it's complementary, not a substitute.
- ✗
Set the IPS action to 'block'
Why it's wrong here
The IPS action parameter—such as 'block', 'monitor', or 'reset'—determines how the FortiGate responds once a signature has already matched. It has no effect on whether the HTTP protocol decoder is enabled; without the decoder, the engine cannot generate a match against HTTP-based attacks in the first place. So setting the action to 'block' does not solve the underlying parsing issue.
- ✗
Disable the FTP protocol decoder
Why it's wrong here
The FTP protocol decoder is a separate component that parses File Transfer Protocol commands and data channels; disabling it would only reduce FTP inspection capabilities. It operates independently of the HTTP decoder, and the presence of FTP typically coexists with HTTP on the same sensor without interference. No requirement exists to disable unrelated decoders to get HTTP inspection working, so this action is both unnecessary and potentially harmful.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.