Courseiva
Security Profiles →hardMultiple Choice

NSE4 Security Profiles Practice Question

A FortiGate is configured with an SSL deep inspection profile that uses 'Certificate Inspection' (not 'Full SSL Inspection'). Which of the following is TRUE about this configuration?

⚠ Common exam trap

Many exam-takers assume 'deep inspection' implies full decryption, but Fortinet distinguishes between Certificate Inspection (no decryption) and Full SSL Inspection (decryption), and the question specifically tests this distinction by asking what is possible without decryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The FortiGate can block HTTPS connections based on the certificate's CN

Certificate Inspection only examines the SSL/TLS certificate presented during the handshake, without decrypting the traffic. Because the FortiGate can read the certificate's Common Name (CN) or Subject Alternative Name (SAN), it can block HTTPS connections based on that information, such as by using a URL filter or application control rule that matches the certificate's CN. This is the only deep inspection action possible without full decryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deep inspection can still see client certificates

    Why it's wrong here

    Client certificates are exchanged inside the TLS handshake only after the encrypted channel is established, and certificate inspection passively observes the server certificate without terminating the TLS session. Therefore, any client certificate remains encrypted and invisible to the FortiGate; deep inspection would be required to intercept it, but the scenario here is certificate inspection, not deep inspection.

  • ✗

    The antivirus profile can scan the HTTPS payload

    Why it's wrong here

    With certificate inspection, the FortiGate never decrypts the HTTPS stream, so the Antivirus profile has no plaintext HTTP payload to scan. The AV engine can only match patterns after decryption, and without a TLS proxy that decrypts and re-encrypts for both endpoints, the encrypted data is simply opaque ciphertext that cannot be inspected.

  • ✓

    The FortiGate can block HTTPS connections based on the certificate's CN

    Why this is correct

    During the TLS handshake, the server's certificate is sent in plaintext, and certificate inspection extracts the Common Name (CN) and Subject Alternative Name (SAN) to make web filtering decisions. The FortiGate can therefore block or allow an HTTPS request before any application data is exchanged, using the certificate's CN as the classification criterion even with no decryption.

  • ✗

    IPS can still inspect the application layer of HTTPS traffic

    Why it's wrong here

    IPS engines must inspect the decoded application-layer protocol stream to match exploit signatures, but certificate inspection leaves the HTTPS payload fully encrypted between client and server. In this mode the IPS can see only TLS metadata and the server certificate, so it cannot identify attack patterns embedded in encrypted HTTP request or response bodies.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.