NSE4 Security Profiles Practice Question
A FortiGate administrator needs to prevent data leakage by blocking the upload of files containing credit card numbers via web traffic. Which THREE components must be configured? (Choose three.)
⚠ Common exam trap
It's easy for candidates to think application control (option A) or antivirus (option D) can detect sensitive data, but they are designed for different purposes—application control manages app usage, and antivirus detects malware, not data patterns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DLP profile with a rule to detect credit card numbers
A DLP (Data Loss Prevention) profile is specifically designed to inspect content for sensitive data patterns, such as credit card numbers, using predefined or custom data patterns. When configured with a rule to detect credit card numbers, the DLP profile can block or log the upload of files containing such data over web traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Application control profile to block file upload applications
Why it's wrong here
Application control profiles identify and block specific applications based on signature, category, or behavior, but they do not inspect the payload for confidential content. Blocking all file-upload applications would disrupt legitimate business workflows and still fail to prevent leakage through allowed applications like webmail, where a user could attach a sensitive file. Data leakage prevention is implemented by DLP profiles, which analyze the content itself, not by restricting the application.
- ✓
DLP profile with a rule to detect credit card numbers
Why this is correct
A DLP profile is the FortiGate component responsible for content inspection to prevent data leakage. It includes predefined signatures for sensitive patterns such as credit card numbers, social security numbers, and other PII, as well as support for custom regular expressions. When a rule detects a match in the traffic, the configured action (block, log, or allow with notification) is enforced. This forms the core detection mechanism needed to stop credit card data from being uploaded.
- ✓
Firewall policy that applies the DLP profile and SSL inspection to the traffic
Why this is correct
A DLP profile only has impact when it is referenced by an active firewall policy that governs the traffic containing the sensitive data. In FortiOS, the security profiles (including DLP and SSL inspection) are attached to the same policy, ensuring the scanned traffic is both inspected and decrypted consistently. If the policy is missing, misconfigured, or has the wrong source/destination, the profile is never invoked and data leakage would go undetected.
- ✗
Antivirus profile to scan the files for malware
Why it's wrong here
An antivirus profile scans payloads for known malware signatures and heuristics, but it is completely blind to structured data patterns such as credit card numbers. Its threat database is designed for malicious executables, not for recognizing sensitive information in web uploads or emails. Therefore, while it protects against malicious files, it does not address data leakage, which is a confidentiality issue rather than a malware issue.
- ✓
SSL deep inspection to decrypt HTTPS traffic
Why this is correct
SSL deep inspection performs a man-in-the-middle interception of TLS sessions, decrypting the payload so that other security profiles can examine it in plaintext. Without this decryption, the DLP scanner only sees encrypted HTTPS data and cannot evaluate it against the credit-card-number regex rules. Consequently, enabling deep inspection in the firewall policy (either full or certificate-based inspection) is a mandatory prerequisite for DLP to work on web traffic.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.