Courseiva
Security Profiles →mediumMultiple Select

NSE4 Application Control Practice Question

A network admin wants to block all traffic from the BitTorrent application. The admin has enabled application control on the firewall policy. Which step is necessary to achieve this?

⚠ Common exam trap

The trap is assuming that all encrypted applications require SSL deep inspection. BitTorrent uses proprietary protocol encryption, not SSL/TLS. Application control can identify BitTorrent without decryption by analyzing unencrypted portions of the traffic, so deep inspection is not needed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the BitTorrent application signature to the application control profile and set action to block

To block BitTorrent traffic, the admin must add the BitTorrent application signature to the application control profile and set the action to block (option B). Application control can detect BitTorrent even though it uses proprietary encryption—FortiGate uses protocol decoders and signature matching on unencrypted handshake data. SSL deep inspection (option E) is not required because BitTorrent does not use SSL/TLS encryption; enabling deep inspection would not help and would add unnecessary overhead. Options A, C, and D are also unnecessary: DNS filter does not block the application itself, proxy-based inspection is not mandatory, and deep inspection (in the profile) is not the correct setting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a DNS filter profile to block BitTorrent tracker domains

    Why it's wrong here

    DNS filtering blocks resolution of tracker domains, yet BitTorrent peers also connect via DHT, magnet links and hard-coded IPs, so traffic still flows. It is tempting because DNS filtering is the right control when the requirement is to block access to named web destinations rather than the application itself.

  • ✓

    Add the BitTorrent application signature to the application control profile and set action to block

    Why this is correct

    Application control profiles act on traffic only when the relevant application signature is present and its action is set to block. Adding the BitTorrent signature with a block action is therefore the necessary step to drop that application's traffic.

  • ✗

    Set the application control inspection mode to proxy-based

    Why it's wrong here

    Proxy-based inspection governs HTTP and HTTPS application signatures; BitTorrent uses its own peer-to-peer protocol on arbitrary ports, so proxy mode cannot identify or block it. It is tempting because proxy inspection is the correct mode for web-category and SaaS application control, but BitTorrent requires flow-based or stream-based application identification.

  • ✗

    Enable 'deep inspection' in the application control profile

    Why it's wrong here

    Deep inspection decodes evasive protocols tunnelling over standard ports, but BitTorrent is already identified by FortiGuard's application signature database, so it adds no blocking capability here. It is tempting because it is genuinely required for applications that hide inside HTTP or TLS, which is a different scenario.

  • ✗

    Enable SSL deep inspection on the firewall policy

    Why it's wrong here

    SSL deep inspection decrypts TLS traffic to inspect encrypted payloads; BitTorrent's peer-to-peer protocol is not TLS-based, so decryption reveals nothing to match against. It is tempting because SSL inspection is correct for blocking applications tunnelled inside HTTPS, but BitTorrent needs application signatures matched by application control itself.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.