NSE4 Security Profiles Practice Question
A FortiGate is configured with an SSL deep inspection profile that uses 'Certificate Inspection' (not 'Full SSL Inspection'). Which of the following is TRUE about this configuration?
⚠ Common exam trap
Many exam-takers assume 'deep inspection' implies full decryption, but Fortinet distinguishes between Certificate Inspection (no decryption) and Full SSL Inspection (decryption), and the question specifically tests this distinction by asking what is possible without decryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The FortiGate can block HTTPS connections based on the certificate's CN
Certificate Inspection only examines the SSL/TLS certificate presented during the handshake, without decrypting the traffic. Because the FortiGate can read the certificate's Common Name (CN) or Subject Alternative Name (SAN), it can block HTTPS connections based on that information, such as by using a URL filter or application control rule that matches the certificate's CN. This is the only deep inspection action possible without full decryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deep inspection can still see client certificates
Why it's wrong here
Client certificates are exchanged inside the TLS handshake only after the encrypted channel is established, and certificate inspection passively observes the server certificate without terminating the TLS session. Therefore, any client certificate remains encrypted and invisible to the FortiGate; deep inspection would be required to intercept it, but the scenario here is certificate inspection, not deep inspection.
- ✗
The antivirus profile can scan the HTTPS payload
Why it's wrong here
With certificate inspection, the FortiGate never decrypts the HTTPS stream, so the Antivirus profile has no plaintext HTTP payload to scan. The AV engine can only match patterns after decryption, and without a TLS proxy that decrypts and re-encrypts for both endpoints, the encrypted data is simply opaque ciphertext that cannot be inspected.
- ✓
The FortiGate can block HTTPS connections based on the certificate's CN
Why this is correct
During the TLS handshake, the server's certificate is sent in plaintext, and certificate inspection extracts the Common Name (CN) and Subject Alternative Name (SAN) to make web filtering decisions. The FortiGate can therefore block or allow an HTTPS request before any application data is exchanged, using the certificate's CN as the classification criterion even with no decryption.
- ✗
IPS can still inspect the application layer of HTTPS traffic
Why it's wrong here
IPS engines must inspect the decoded application-layer protocol stream to match exploit signatures, but certificate inspection leaves the HTTPS payload fully encrypted between client and server. In this mode the IPS can see only TLS metadata and the server certificate, so it cannot identify attack patterns embedded in encrypted HTTP request or response bodies.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.