NSE4 Security Profiles Practice Question
A FortiGate administrator needs to prevent employees from using peer-to-peer file sharing applications such as BitTorrent. The administrator creates an application control profile with a rule to block the 'Peer-to-Peer' application category. After applying the profile to the firewall policy, users can still use BitTorrent. What is the most likely cause?
⚠ Common exam trap
NSE4 often tests the default action of application control rules, and candidates may assume that adding a category to a profile automatically blocks it, when in fact the action must be explicitly set to Block.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The application control profile is set to 'Monitor' instead of 'Block' for the Peer-to-Peer category.
In FortiGate application control, each application category can be set to 'Block', 'Monitor', or 'Allow'. If the administrator creates a profile with a rule for the 'Peer-to-Peer' category but leaves the action as 'Monitor' (the default in some cases), the FortiGate will only log the traffic and not block it. Therefore, users can still use BitTorrent. The most likely cause is that the action is set to Monitor instead of Block.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The application control profile is applied to the outbound policy but not to the inbound policy.
Why it's wrong here
Applying the application control profile only to the outbound policy is correct because employees generate the BitTorrent traffic as they access external peers; an inbound policy would govern external-originated traffic trying to enter the internal network. Since the problem is about preventing employees from using BitTorrent, the outbound policy is precisely where the profile must sit. Therefore, this config is not a fault; it is the opposite of a misconfiguration.
- ✓
The application control profile is set to 'Monitor' instead of 'Block' for the Peer-to-Peer category.
Why this is correct
In FortiOS, an application control profile defines per-category actions such as Monitor, Allow, or Block. If the Peer-to-Peer category is left as 'Monitor', the FortiGate identifies BitTorrent, writes a log entry, but still forwards the packets, so employees can keep using it. Only changing the action to 'Block' (or adding a specific BitTorrent rule with block) will actually deny the traffic. Thus, the correct fix is to edit the profile's Peer-to-Peer setting to enforce blocking rather than merely monitoring.
- ✗
BitTorrent is not a recognized application in the FortiGuard application control database.
Why it's wrong here
The FortiGuard application control database has long included BitTorrent as a signature, and it is automatically grouped under the Peer-to-Peer category alongside applications such as uTorrent and eMule. Because the profile already matches the traffic (as confirmed by the 'Monitor' action), the problem is not a missing database entry. Choosing this option misreads the situation: the application is recognized, just not stopped.
- ✗
The firewall policy has SSL inspection set to certificate inspection, so the FortiGate cannot see the application.
Why it's wrong here
Certificate inspection only examines the TLS handshake and certificate details without decrypting the payload, but application control does not rely solely on decryption; it uses flow-based signatures, protocol decoders, and even SNI information to identify BitTorrent. Many BitTorrent connections occur over plaintext or use distinctive handshake patterns, so the FortiGate can still detect the application even with certificate inspection enabled. The real reason traffic is permitted is the profile's Monitor action, not the inability to see encrypted content.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.