Courseiva
Security Profiles →mediumMultiple Select

NSE4 Security Profiles Practice Question

A FortiGate administrator is troubleshooting why antivirus scanning is not working for HTTPS traffic. Which TWO steps should be verified?

⚠ Common exam trap

Test-takers frequently assume proxy-based inspection is required for HTTPS antivirus scanning, but the critical step is enabling SSL/TLS deep inspection on the firewall policy, regardless of the inspection mode.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure the firewall policy has SSL/TLS deep inspection enabled

HTTPS traffic is encrypted, so the FortiGate must decrypt it using SSL/TLS deep inspection before the antivirus engine can scan the payload. Without deep inspection, the antivirus profile sees only encrypted packets and cannot detect threats within the HTTPS stream.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ensure the antivirus profile is set to proxy-based inspection

    Why it's wrong here

    The antivirus profile's inspection mode (proxy-based vs flow-based) is orthogonal to whether HTTPS payloads are visible for scanning. FortiGate can scan decrypted HTTPS traffic equally in flow or proxy mode once deep inspection is enabled; proxy mode is not a prerequisite for AV detection. The clue that antivirus is not detecting SSL traffic points to missing decryption, not the inspection mode setting.

  • ✓

    Ensure the firewall policy has SSL/TLS deep inspection enabled

    Why this is correct

    Without SSL/TLS deep inspection enabled on the firewall policy, HTTPS sessions pass through still encrypted, and the antivirus engine can only see the outer TLS handshake, not the HTTP payload or files inside. Deep inspection forces the FortiGate to terminate the TLS connection, decrypt the content, scan it with the antivirus profile, then re-encrypt the session to the client. This is the most likely root cause when antivirus misses malware in HTTPS traffic, since the profile itself may be correctly configured but cannot see inside the tunnel.

  • ✗

    Confirm that the web filter profile is also applied

    Why it's wrong here

    A web filter profile is responsible for URL categorization, domain blocking, and content filtering, not for malware detection. Antivirus scanning operates independently under the security profiles attached to the firewall policy, using the FortiGuard antivirus database. Adding a web filter profile would not enable antivirus scanning of HTTPS traffic and is unrelated to the reported symptom, so this action does not resolve the issue.

  • ✓

    Verify that the antivirus profile is applied to the policy

    Why this is correct

    Verifying that the antivirus profile is actually applied to the firewall policy is a valid and necessary troubleshooting step, and it is one of the two correct answers here. A FortiGate can have antivirus profiles defined globally, but if the profile is not explicitly selected in the policy's security profiles section, no scanning occurs. This is a common misconfiguration, especially when policies are duplicated or inherited from a template, and might be the reason antivirus is not catching threats.

  • ✗

    Check that the FortiSandbox is online for advanced scanning

    Why it's wrong here

    FortiSandbox is an advanced threat detection service used to analyze suspicious files in a sandbox environment, and it is an optional supplement to the FortiGate's antivirus scanning. Basic antivirus scanning relies on the FortiGuard antivirus signatures and does not require FortiSandbox to be online or licensed. The issue described is about antivirus not scanning HTTPS traffic at all, which is a decryption or profile application problem, not a lack of sandbox integration.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.