NSE4 Security Profiles Practice Question
A network administrator is troubleshooting why certain web-based applications are not being identified by application control. The applications are accessed over HTTPS. What is the most likely missing configuration?
⚠ Common exam trap
Many exam-takers confuse 'deep packet inspection' with 'SSL inspection,' but DPI is a broader concept that includes many inspection types, and the specific missing piece for HTTPS application identification is SSL inspection, not DPI as a whole.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSL inspection is not configured and applied to the firewall policy.
Application control relies on inspecting the content of traffic to identify applications. When traffic is encrypted with HTTPS, the firewall cannot inspect the payload without decrypting it first. Therefore, SSL inspection must be configured and applied to the firewall policy to allow the FortiGate to decrypt the traffic and match it against application control signatures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Web filter profile is not applied to the firewall policy.
Why it's wrong here
Web filter profiles in FortiOS control URL access by categorizing domain names and paths, not by identifying the application generating the traffic. Application control is a separate security profile that uses protocol decoders and FortiGuard signatures on the session payload, independent of the web filter. Not applying a web filter profile would only leave URL categorization unmanaged; it would not prevent the firewall from recognizing applications. Therefore, the missing web filter profile is unrelated to the inability to identify certain web-based apps.
- ✓
SSL inspection is not configured and applied to the firewall policy.
Why this is correct
Application control must inspect the contents of an HTTP conversation to identify the application; but when the session is HTTPS, the payload is encrypted and opaque to the security engine. Without an SSL/SSH inspection profile applied to the firewall policy, FortiGate sees only the TLS handshake and the SNI field, so the protocol decoders cannot match application signatures. Enabling SSL inspection decrypts the HTTPS stream and makes the full payload available to application control. Therefore, the correct fix is to add and apply an SSL inspection profile on the same firewall policy that carries the application control profile.
- ✗
Deep packet inspection is not enabled on the firewall policy.
Why it's wrong here
On FortiOS there is no single 'deep packet inspection' toggle; inspection depth is determined by which security profiles are attached to the policy, such as application control, IPS, web filter, and SSL inspection. While application control and IPS both inspect packet payloads, HTTPS traffic cannot be evaluated beyond the initial handshake unless an SSL/SSH inspection profile decrypts it. Saying 'deep packet inspection is not enabled' is imprecise, and even if it were enabled, applications would still be invisible inside TLS without decryption. The real prerequisite for seeing inside HTTPS sessions is SSL inspection, not a generic DPI switch.
- ✗
IPS is not enabled on the firewall policy.
Why it's wrong here
IPS is designed to detect known attack signatures, protocol anomalies, and exploit attempts by inspecting network, transport, and application payloads. In contrast, application control uses the FortiGuard application identification database and protocol logic to classify which application is in use, and it works independently of the IPS engine. Disabling IPS would only remove intrusion-prevention coverage—it would not prevent the firewall from identifying applications. Consequently, this option misdiagnoses the absence of application classification as an IPS misconfiguration, when the true root cause is missing SSL inspection.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.