Courseiva
Security Profiles →mediumMultiple Choice

NSE4 Security Profiles Practice Question

An administrator applies an application control profile to a firewall policy that allows outbound traffic. Users report that a specific business-critical application, which uses TLS on port 443, is now being blocked even though the application is not listed as blocked in the profile. The administrator wants to allow this application while still controlling other applications. What is the most likely reason the application is being blocked?

⚠ Common exam trap

The trap here is assuming that only explicitly blocked applications are blocked, while overlooking the default action for unknown applications.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The application control profile is configured to block all applications that are not explicitly allowed.

The correct answer is that the application control profile is configured to block all applications that are not explicitly allowed. In FortiGate application control, each category and application can have an action, and there is a default action for applications not explicitly listed. If the default action is set to block, any application not in the allow list will be blocked, even if it is not explicitly blocked. The administrator should either add the application to the allow list or change the default action to allow.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The firewall policy is using flow-based inspection, which cannot identify applications on port 443.

    Why it's wrong here

    Flow-based inspection can identify applications on port 443, though proxy-based inspection provides more granular control. The issue is not the inspection mode but the application control profile's default action. Flow-based inspection supports application control and can detect applications based on protocol and behavior.

  • ✗

    The application is being blocked by a separate IPS sensor that is applied to the same firewall policy.

    Why it's wrong here

    An IPS sensor blocks based on vulnerability signatures, not application identity. While an IPS sensor could block traffic that matches a signature, the scenario states the application is blocked by the application control profile. The most likely cause is the application control profile's default action for unknown applications.

  • ✗

    The application control profile requires an SSL inspection profile to detect applications on port 443, and none is applied.

    Why it's wrong here

    While SSL inspection can help identify applications within encrypted traffic, application control can still detect applications based on other characteristics such as server certificate, IP reputation, and traffic patterns. The lack of SSL inspection alone would not cause a complete block of the application unless the profile is set to block encrypted traffic.

  • ✓

    The application control profile is configured to block all applications that are not explicitly allowed.

    Why this is correct

    When an application control profile is set to block unknown applications or has a default action of block for categories not explicitly allowed, applications not recognized or not listed may be blocked. This is a common misconfiguration where the administrator must either add the application to an allow list or adjust the default action to allow.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.