Configuring SSL Inspection for Self-Signed Certificates on Non-Standard Ports
A network administrator notices that HTTP traffic is being scanned by the antivirus profile, but HTTPS traffic to the same web server is not being scanned. The firewall policy has the antivirus profile applied and SSL inspection is set to 'certificate-inspection'. What is the most likely reason HTTPS traffic is not being scanned?
⚠ Common exam trap
It's easy for candidates to assume 'certificate-inspection' implies some level of content scanning, but it only validates the certificate and does not decrypt the traffic for security profile inspection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Certificate inspection does not decrypt the traffic, so the antivirus scanner cannot inspect the payload.
Certificate inspection only validates the SSL/TLS certificate without decrypting the traffic. Since the antivirus scanner requires access to the plaintext payload to detect threats, it cannot scan HTTPS traffic when only certificate inspection is configured. This is why HTTP traffic is scanned but HTTPS traffic is not.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Certificate inspection does not decrypt the traffic, so the antivirus scanner cannot inspect the payload.
Why this is correct
Certificate inspection only validates the server certificate's identity and trust chain; it does not terminate the TLS session or decrypt the stream. Consequently, the FortiGate forwards the encrypted HTTP payload unchanged, and the antivirus engine sees only ciphertext. Since malware signatures cannot be matched against encrypted bytes, the antivirus profile simply cannot inspect what it cannot see, which is exactly why HTTP traffic appears to bypass scanning.
- ✗
The antivirus profile is configured in flow mode, which does not support scanning HTTPS traffic.
Why it's wrong here
Flow mode is a scanning mode that processes traffic in a single pass, and it fully supports HTTPS scanning when a deep inspection profile is configured to decrypt the session. The deciding factor is not flow versus proxy mode but whether the policy applies decryption at all. If only certificate inspection were used, flow mode would also fail to see the plaintext, so blaming flow mode is a misdiagnosis.
- ✗
The web server is not using a cipher supported by the FortiGate.
Why it's wrong here
An unsupported cipher would cause the TLS handshake to fail or negotiate a different cipher, typically resulting in a connection error or alert, not a silent bypass of antivirus scanning. Even if the cipher were weak, the FortiGate would still need the session key or the server's private key to decrypt traffic; cipher support alone does not determine inspection capability. Thus the cipher is irrelevant to why AV misses the encrypted payload.
- ✗
The FortiGate is using proxy-based inspection, which does not support HTTPS scanning.
Why it's wrong here
Proxy-based inspection actually provides deeper visibility than flow mode and, when combined with deep inspection, can decrypt and scan HTTPS traffic thoroughly. It is a common misconception that proxy mode lacks HTTPS scanning; the real requirement is that the firewall policy must use a full SSL inspection profile to perform the man-in-the-middle decryption. Since certificate inspection does not decrypt, the proxy engine is simply never given cleartext to scan.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.