NSE4 Security Profiles Practice Question
A network administrator configures an application control profile to block social media applications. Users can still access Facebook through a web browser. What is the MOST likely reason?
⚠ Common exam trap
Many exam-takers assume application control works on all traffic by default, overlooking that HTTPS encryption hides application signatures and requires explicit deep inspection configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Application control is not enabled for HTTPS traffic without deep inspection
Application control relies on deep inspection (SSL/TLS decryption) to identify applications within encrypted HTTPS traffic. Without deep inspection enabled, the FortiGate can only see the encrypted tunnel and cannot inspect the payload to determine that the traffic is Facebook, even if the application control profile is correctly applied. Option B is correct because HTTPS traffic must be decrypted via deep inspection for application control to function.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The application signatures are outdated
Why it's wrong here
Outdated signatures are a red herring here. While signature updates improve detection of new or modified applications, Facebook's core application traffic is well-established and has been covered by standard application-control signatures for years. Even an older signature database can reliably identify Facebook's primary HTTP/HTTPS connections. Also, FortiGate application control combines signature matching with behavioral heuristics, so blocking a major application like Facebook does not hinge on having the latest signature update.
- ✓
Application control is not enabled for HTTPS traffic without deep inspection
Why this is correct
This is the root cause. Facebook uses HTTPS by default, and application control identifies applications by inspecting the content and patterns within the traffic flow. Without SSL/TLS deep inspection (also called SSL inspection or decryption), the FortiGate only sees the encrypted payload and cannot match the application signature against the actual application data. While it might see the SNI (Server Name Indication) field or the destination IP, that information can be misleading or blocked by TLS 1.3 encrypted SNI, so the firewall cannot confidently identify Facebook as the application. Therefore, enabling deep inspection in the firewall policy is mandatory for application control to work on HTTPS traffic.
- ✗
The firewall policy is in proxy-based mode
Why it's wrong here
Proxy-based mode is not the issue because it does not prevent application control; in fact, proxy-based inspection reassembles and fully buffers traffic, which can even improve application identification. The firewall mode (proxy-based or flow-based) determines how packets are processed, but both modes support deep inspection. If deep inspection is not enabled, neither mode can see inside the encrypted HTTPS stream to identify the application. The problem lies in the missing SSL inspection, not the proxy/flow processing mode.
- ✗
The application control profile is not applied to the correct policy
Why it's wrong here
If the application control profile were not applied to the correct policy, the user would likely see no application control enforcement at all — not just a failure to block Facebook over HTTPS. The scenario implies that the administrator has configured and applied an application control profile, otherwise the question would be pointless. A common oversight, however, is applying the profile to the policy but forgetting to enable deep inspection within that same policy. Thus, the application control profile is in place, but it cannot see the encrypted content to take action.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.