Courseiva
Security Profiles →hardMultiple Choice

NSE4 Security Profiles Practice Question

A FortiGate administrator needs to configure a policy so that traffic to a specific external server is exempted from SSL deep inspection. Which method should be used?

⚠ Common exam trap

It's easy for candidates to think they must create a separate firewall policy to bypass SSL inspection, but FortiGate's design intentionally centralizes SSL exemption within the inspection profile to maintain policy simplicity and avoid unintended security gaps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the server's address to the 'SSL/SSH Inspection Profile' exemptions list

The SSL/SSH Inspection Profile includes an 'Exemptions' list where you can specify destination addresses that should bypass SSL deep inspection. This allows traffic to a specific external server to be excluded from SSL inspection without creating a separate firewall policy, ensuring that other security profiles (like antivirus, IPS, and web filtering) still apply to that traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add the server's address to the 'SSL/SSH Inspection Profile' exemptions list

    Why this is correct

    The Exemptions list inside an SSL/SSH Inspection Profile lets the administrator define destination addresses that FortiGate should not attempt to decrypt, even though the deep-inspection profile remains attached to the firewall policy. Matched traffic is allowed to pass through the gateway without a TLS/SSL man-in-the-middle re-signing handshake, so it avoids certificate-validation failures for servers that use certificate pinning or restricted ciphers. This is the recommended approach because it keeps the policy architecture clean and confines exception handling to the inspection profile itself.

  • ✗

    Create a separate firewall policy without SSL inspection for that server

    Why it's wrong here

    Creating a second firewall policy without an SSL/SSH Inspection profile for that server can technically work, but it forces the administrator to duplicate every other security setting from the original policy and to carefully manage policy order so the no-inspection rule doesn't accidentally match other traffic. It also undermines consistent logging and reporting because the server's traffic would be governed by a completely different policy path, making audits harder. Fortinet recommends centralizing bypass decisions in the SSL/SSH inspection profile's exemptions rather than proliferating firewall policies.

  • ✗

    Disable the IPS sensor on that policy

    Why it's wrong here

    Disabling the IPS sensor in the firewall policy has no effect on SSL deep inspection because IPS inspection is a post-decryption function that examines already-decrypted traffic. If the SSL/SSH Inspection Profile remains enabled, FortiGate will still perform the TLS man-in-the-middle handshake and decrypt the flow; the only result of disabling IPS is that decrypted content will no longer be evaluated for intrusion attempts. The decryption process itself is controlled exclusively by the SSL/SSH Inspection Profile attached to the policy, not by any other security profile.

  • ✗

    Set the antivirus profile to 'monitor' only

    Why it's wrong here

    Switching the antivirus profile to 'monitor' (log-only) changes what FortiGate does after it detects malicious content in a decrypted stream, but it does not change whether or when traffic is decrypted. With an SSL/SSH Inspection Profile still applied, the gateway continues to intercept and decrypt the TLS session, so the AV engine still receives plaintext content for scanning—it just logs rather than blocks when a malware signature matches. SSL inspection is a separate functional layer whose activation depends solely on the SSL/SSH Inspection Profile, not on the AV profile's action settings.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.