Courseiva
Security Profiles →mediumMultiple Choice

NSE4 Security Profiles Practice Question

After enabling SSL inspection, a user receives a warning 'The certificate is not trusted' in the browser. The administrator has installed the CA certificate on the client. What else could be the cause?

⚠ Common exam trap

Watch out — candidates often assume installing the CA certificate on the client OS is sufficient for all browsers, but browsers like Firefox maintain their own certificate trust store, and even Chrome on some platforms may require the certificate to be in the correct store (e.g., the 'Trusted Root Certification Authorities' store) for the warning to disappear.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The CA certificate is not added to the browser's trusted root store.

Even though the administrator installed the CA certificate on the client, the browser uses its own trusted root store, which is separate from the operating system's certificate store. If the CA certificate is not specifically added to the browser's trusted root store (e.g., Chrome uses the system store but Firefox maintains its own), the browser will still flag the certificate as untrusted. This is a common misconfiguration when deploying SSL inspection with FortiGate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The firewall policy denies the traffic.

    Why it's wrong here

    If the firewall policy denied the traffic, the client's connection request would never reach the FortiGate's SSL inspection proxy. Instead, the browser would receive a TCP reset, a 'connection refused' error, or a timeout — not a certificate trust warning. A certificate warning can only appear after the traffic has been permitted by policy and the deep inspection proxy has intercepted the TLS handshake, so a deny action (even implicitly) cannot produce the symptom described.

  • ✓

    The CA certificate is not added to the browser's trusted root store.

    Why this is correct

    When SSL inspection is enabled on the FortiGate, it terminates the client's TLS connection and re-signs a new certificate for the requested website using its own local Certificate Authority. The browser will only trust this dynamically generated certificate if the FortiGate's CA certificate has been installed in the client's trusted root certificate store. If that CA is missing or untrusted, the browser warns that the certificate was not issued by a trusted authority, which is exactly the warning the user sees — this is the correct cause of the issue.

  • ✗

    The FortiGate is not decrypting the traffic.

    Why it's wrong here

    If the FortiGate were not decrypting the traffic, it would simply pass the encrypted TLS stream through to the destination server. The browser would receive the original server certificate and validate it against its existing trust store, so no FortiGate-related certificate warning would appear. A warning mentioning the FortiGate's CA can only be generated after decryption and re-encryption have occurred, meaning this option describes a state that would prevent the symptom rather than cause it.

  • ✗

    The web server's certificate has expired.

    Why it's wrong here

    With SSL inspection active, the FortiGate presents its own locally generated certificate to the browser, not the original web server certificate. Consequently, the browser checks the validity period of the FortiGate-generated certificate, which typically has a validity of only a few days or weeks, rather than the actual server certificate's expiration date. An expired server certificate would yield a 'certificate expired' error if inspection were disabled, but in this inspected session it is not the direct trigger for the user's trust warning.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.