NSE4 Security Profiles Practice Question
A FortiGate administrator needs to configure a policy so that traffic to a specific external server is exempted from SSL deep inspection. Which method should be used?
⚠ Common exam trap
It's easy for candidates to think they must create a separate firewall policy to bypass SSL inspection, but FortiGate's design intentionally centralizes SSL exemption within the inspection profile to maintain policy simplicity and avoid unintended security gaps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the server's address to the 'SSL/SSH Inspection Profile' exemptions list
The SSL/SSH Inspection Profile includes an 'Exemptions' list where you can specify destination addresses that should bypass SSL deep inspection. This allows traffic to a specific external server to be excluded from SSL inspection without creating a separate firewall policy, ensuring that other security profiles (like antivirus, IPS, and web filtering) still apply to that traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add the server's address to the 'SSL/SSH Inspection Profile' exemptions list
Why this is correct
The Exemptions list inside an SSL/SSH Inspection Profile lets the administrator define destination addresses that FortiGate should not attempt to decrypt, even though the deep-inspection profile remains attached to the firewall policy. Matched traffic is allowed to pass through the gateway without a TLS/SSL man-in-the-middle re-signing handshake, so it avoids certificate-validation failures for servers that use certificate pinning or restricted ciphers. This is the recommended approach because it keeps the policy architecture clean and confines exception handling to the inspection profile itself.
- ✗
Create a separate firewall policy without SSL inspection for that server
Why it's wrong here
Creating a second firewall policy without an SSL/SSH Inspection profile for that server can technically work, but it forces the administrator to duplicate every other security setting from the original policy and to carefully manage policy order so the no-inspection rule doesn't accidentally match other traffic. It also undermines consistent logging and reporting because the server's traffic would be governed by a completely different policy path, making audits harder. Fortinet recommends centralizing bypass decisions in the SSL/SSH inspection profile's exemptions rather than proliferating firewall policies.
- ✗
Disable the IPS sensor on that policy
Why it's wrong here
Disabling the IPS sensor in the firewall policy has no effect on SSL deep inspection because IPS inspection is a post-decryption function that examines already-decrypted traffic. If the SSL/SSH Inspection Profile remains enabled, FortiGate will still perform the TLS man-in-the-middle handshake and decrypt the flow; the only result of disabling IPS is that decrypted content will no longer be evaluated for intrusion attempts. The decryption process itself is controlled exclusively by the SSL/SSH Inspection Profile attached to the policy, not by any other security profile.
- ✗
Set the antivirus profile to 'monitor' only
Why it's wrong here
Switching the antivirus profile to 'monitor' (log-only) changes what FortiGate does after it detects malicious content in a decrypted stream, but it does not change whether or when traffic is decrypted. With an SSL/SSH Inspection Profile still applied, the gateway continues to intercept and decrypt the TLS session, so the AV engine still receives plaintext content for scanning—it just logs rather than blocks when a malware signature matches. SSL inspection is a separate functional layer whose activation depends solely on the SSL/SSH Inspection Profile, not on the AV profile's action settings.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.