NSE4 Security Profiles Practice Question
A FortiGate is configured with SSL inspection and web filtering. The administrator notices that some HTTPS traffic is being blocked even though the URL is in an allowed category. What could be the cause?
⚠ Common exam trap
Many exam-takers assume web filtering categories alone control HTTPS traffic, forgetting that SSL inspection's certificate validation can preemptively block sessions even for allowed URLs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SSL inspection profile has 'certificate-validation-failed' action set to 'block'.
When SSL inspection is enabled, the FortiGate acts as a man-in-the-middle and validates the server's certificate. If the certificate is invalid (e.g., expired, self-signed, or mismatched), the FortiGate can block the session based on the 'certificate-validation-failed' action in the SSL inspection profile. Even if the URL belongs to an allowed web filter category, a failed certificate validation will cause the traffic to be blocked before the web filter policy is applied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The FortiGate's DNS server is not resolving the domain correctly.
Why it's wrong here
If the FortiGate's configured DNS servers cannot resolve the fully qualified domain name, the web filter cannot perform a URL category lookup because it has no IP or hostname to match against. This condition usually results in an NXDOMAIN response and a connection failure, not a certificate-based block after the TLS handshake begins. Since the traffic never reaches the server, an SSL inspection profile's 'certificate-validation-failed' action would not even be triggered, making this explanation inconsistent with the reported symptom.
- ✗
The web filter's 'allow' list is misconfigured.
Why it's wrong here
An 'allow' list in a web filter profile is an override that explicitly permits specified URLs or domains even if their category would normally be blocked. A misconfigured allow list would cause traffic to be permitted when it should be denied, not blocked when it should be allowed. Because the user is experiencing a block, the cause cannot be an allow list entry; moreover, the block is described as occurring during SSL inspection, which evaluates certificate validity before the web filter determines whether the URL is allowed.
- ✗
The web filter profile has 'safe-search' enabled.
Why it's wrong here
Safe-search is a web filter feature that forces supported search engines to omit explicit results by adding parameters such as 'safe=active' to search queries, but it does not block access to whole websites and has no effect on TLS certificate validation. If enabled, safe-search would only alter the content of search engine results after the SSL connection has been established and decrypted. It cannot generate a block page or connection reset based on a certificate failure, so this option does not explain the described behavior.
- ✓
The SSL inspection profile has 'certificate-validation-failed' action set to 'block'.
Why this is correct
When an SSL inspection profile has the 'certificate-validation-failed' action set to 'block', the FortiGate actively terminates the TLS handshake whenever the server certificate fails validation, such as due to an expired certificate, an untrusted CA, or a hostname mismatch. This action is evaluated during the SSL inspection proxy phase, before any decrypted content is passed to the web filter for URL categorisation. Consequently, the user sees a connection reset or block page even though the web filter profile itself may have no rule blocking the URL. This direct cause-and-effect matches the scenario exactly.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.