Courseiva

NSE4 High Availability and Diagnostics Practice Question

A FortiGate administrator needs to ensure that a specific traffic flow is fully inspected by the antivirus and IPS profiles. The traffic is HTTPS. Which THREE configuration items are required? (Select three.)

⚠ Common exam trap

NSE4 often tests the misconception that simply applying antivirus and IPS profiles to a policy is enough to inspect HTTPS traffic, but without SSL deep inspection, the FortiGate cannot see inside the encrypted tunnel, so the profiles are ineffective.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply an IPS profile to the firewall policy

Option B is correct because an IPS profile must be attached to the firewall policy for the FortiGate to inspect the traffic flow for intrusions and exploits. Option C is correct because an antivirus profile must also be applied to the firewall policy so that the same traffic is scanned for malware and viruses. Option D is correct because the traffic is HTTPS, so SSL/TLS deep inspection must be enabled on the firewall policy to decrypt the traffic and allow the antivirus and IPS engines to inspect the payload. Option A is not required because flow-based inspection mode is a global inspection setting and is not a mandatory item for applying antivirus and IPS profiles to a specific HTTPS policy. Option E is not required because a DNS filter profile is used for DNS security filtering and does not enable antivirus or IPS inspection of HTTPS traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable flow-based inspection mode globally

    Why it's wrong here

    Enabling flow-based inspection mode globally changes the inspection engine for all traffic but does not by itself attach any security profile to the specific policy. It merely alters how profiles (if applied) process traffic; without an IPS or antivirus profile on the firewall policy, no intrusion or malware detection occurs. You can achieve the required inspection with proxy-based mode as well, so this is not a necessary action.

  • ✓

    Apply an IPS profile to the firewall policy

    Why this is correct

    An IPS profile contains signatures and anomaly detection rules that inspect traffic for known vulnerabilities, exploits, and attack patterns. By applying this profile to the firewall policy, the FortiGate can block malicious packets in real time, which directly addresses the requirement to secure the specific traffic flow. Without the profile, even with flow-based inspection enabled, the device would not have the rulebase to identify intrusion attempts.

  • ✓

    Apply an antivirus profile to the firewall policy

    Why this is correct

    An antivirus profile enables FortiGate's malware scanning engine to examine files and payloads traversing the policy for viruses, worms, and trojans. This is essential when the requirement includes preventing malicious software from reaching the internal network. The profile must be explicitly associated with the firewall policy; simply having the security fabric or inspection mode enabled does not perform content scanning.

  • ✓

    Enable SSL/TSL deep inspection on the firewall policy

    Why this is correct

    Many modern attacks hide inside HTTPS sessions. Enabling SSL/TLS deep inspection on the policy allows the FortiGate to decrypt outbound or inbound SSL/TLS traffic, apply the IPS and antivirus profiles to the plaintext content, and then re-encrypt it before forwarding. If no deep inspection is enabled, FortiGate sees only encrypted bytes, so the IPS and antivirus profiles would be ineffective against encrypted threats. Therefore, deep inspection is a prerequisite for the security profiles to see the actual payload.

  • ✗

    Configure a DNS filter profile

    Why it's wrong here

    A DNS filter profile controls which domains users can resolve by inspecting DNS queries and responses, often for web filtering or blocking malicious destinations. It does not perform deep packet inspection on HTTPS content, does not scan for malware in the traffic flow, and cannot block intrusion attempts inside an encrypted session. While DNS filtering may be a complementary security control, it does not satisfy the requirement to inspect the specific traffic for vulnerabilities or malware.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.