NSE4 Security Profiles Practice Question
A FortiGate administrator is troubleshooting an issue where a user receives a certificate error when accessing a web server. The administrator has configured SSL deep inspection with a custom CA certificate. The error indicates the certificate is not trusted. Which THREE actions could resolve this issue? (Choose three.)
⚠ Common exam trap
NSE4 often tests the misconception that simply enabling deep inspection is enough, forgetting that the client must trust the FortiGate's CA — or that certificate-inspection and exemption are valid alternatives when deep inspection is not feasible.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install the FortiGate's CA certificate on the client devices.
Option A is correct because with SSL deep inspection the FortiGate re-signs the server certificate using its custom CA, so that CA certificate must be imported into the client's trust store (e.g., Windows Certificate Manager or browser trust store) for the re-signed certificate to validate without an untrusted-CA error. Option D is correct because switching the profile to certificate-inspection means the FortiGate only inspects the certificate metadata (SNI, CN, validity) and does not re-sign the server certificate, so the client sees the original, publicly trusted server certificate and no trust error occurs. Option E is correct because adding the web server to the SSL exemption list in the inspection profile bypasses deep inspection for that destination, again letting the client receive the original trusted certificate. Option B is not the intended fix because disabling SSL inspection entirely removes security inspection rather than resolving the trust problem while preserving inspection. Option C is not relevant because a firmware update does not make the client trust the FortiGate's custom CA certificate or change the re-signing behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Install the FortiGate's CA certificate on the client devices.
Why this is correct
Deep inspection performs man-in-the-middle interception, presenting a dynamically generated certificate signed by the FortiGate's own CA to the client. If that CA is not in the client's trusted root store, the browser reports a certificate error. Installing the FortiGate's CA certificate on client devices establishes trust for all re-issued certificates, which resolves the error while preserving full inspection of the decrypted payload.
- ✗
Disable SSL inspection on the firewall policy entirely.
Why it's wrong here
Disabling SSL inspection entirely would remove the certificate re-signing and eliminate the error, but it also strips all visibility into encrypted traffic on the policy. This is a blunt, network-wide change that sacrifices security controls for one connectivity issue, and it does not address the root cause—the client's lack of trust in the FortiGate's CA. An administrator would lose the ability to block threats or enforce acceptable-use policies inside TLS sessions.
- ✗
Update the FortiGate firmware to the latest version.
Why it's wrong here
FortiGate firmware updates address software bugs and add features, but a certificate trust error stems from the client not recognizing the inspection CA, not from a defect in the FortiGate's SSL inspection engine. Upgrading the firmware does not modify the CA certificate that signs the re-issued certificates, nor does it propagate trust to client devices. Unless a specific bug in certificate generation is documented, a firmware update is unrelated to the problem and will have no effect.
- ✓
Change the SSL inspection profile to 'certificate-inspection' instead of 'deep-inspection'.
Why this is correct
Switching from deep inspection to certificate-inspection mode is a valid fix because certificate-inspection does not re-sign the server's certificate; it only examines the TLS handshake metadata and forwards the original certificate. The client receives the web server's legitimate certificate, which is already trusted, so the TLS handshake succeeds without warnings. The trade-off is that certificate-inspection cannot decrypt or scan the HTTP payload, reducing visibility into the content of encrypted sessions.
- ✓
Add the web server to the SSL exemption list in the SSL inspection profile.
Why this is correct
The SSL exemption list in the inspection profile allows administrators to exclude specific servers or domains from deep inspection, so those connections are passed through without man-in-the-middle re-signing. This preserves the original server certificate, which the client trusts, and eliminates the error for that particular traffic. It is a selective fix that keeps deep inspection enabled for all other web servers, minimizing the security impact while resolving the targeted issue.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.