Courseiva
Security ProfilesmediumMultiple SelectObjective-mapped

NSE4 Application Control Practice Question

A network admin wants to block all traffic from the BitTorrent application. The admin has enabled application control on the firewall policy. Which step is necessary to achieve this?

⚠ Common exam trap

The trap is assuming that all encrypted applications require SSL deep inspection. BitTorrent uses proprietary protocol encryption, not SSL/TLS. Application control can identify BitTorrent without decryption by analyzing unencrypted portions of the traffic, so deep inspection is not needed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Add the BitTorrent application signature to the application control profile and set action to block

To block BitTorrent traffic, the admin must add the BitTorrent application signature to the application control profile and set the action to block (option B). Application control can detect BitTorrent even though it uses proprietary encryption—FortiGate uses protocol decoders and signature matching on unencrypted handshake data. SSL deep inspection (option E) is not required because BitTorrent does not use SSL/TLS encryption; enabling deep inspection would not help and would add unnecessary overhead. Options A, C, and D are also unnecessary: DNS filter does not block the application itself, proxy-based inspection is not mandatory, and deep inspection (in the profile) is not the correct setting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Add a DNS filter profile to block BitTorrent tracker domains

    Why it's wrong here

    Incorrect. DNS filter blocks domains, but BitTorrent can use multiple trackers or peer discovery methods; DNS filter alone is not sufficient to block the application.

  • Add the BitTorrent application signature to the application control profile and set action to block

    Why this is correct

    Correct. Adding the BitTorrent signature to the application control profile and blocking it will directly prevent the traffic.

  • Set the application control inspection mode to proxy-based

    Why it's wrong here

    Incorrect. The inspection mode (proxy-based or flow-based) does not determine whether BitTorrent can be blocked; application control works in both modes.

  • Enable 'deep inspection' in the application control profile

    Why it's wrong here

    Incorrect. 'Deep inspection' in the application control profile refers to inspecting beyond basic signatures, but it is not specifically required for BitTorrent.

  • Enable SSL deep inspection on the firewall policy

    Why it's wrong here

    Incorrect. BitTorrent uses proprietary encryption, not SSL/TLS. SSL deep inspection will not decrypt BitTorrent traffic and is not necessary for application control to detect and block it.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every NSE4 question from scratch — 282 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.