NSE4 Security Profiles Practice Question
An administrator configured SSL inspection with 'deep-inspection' profile. Users report that some websites fail to load with certificate errors. The firewall policy is correct. What is the most likely reason?
⚠ Common exam trap
Test-takers frequently assume certificate errors are always due to an expired CA certificate, but the question specifies that only some websites fail, which points to a cipher mismatch during re-encryption rather than a global CA issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The web server uses a cipher that the FortiGate cannot re-encrypt.
When deep-inspection is used, the FortiGate decrypts the client-to-server traffic, inspects the content, and then re-encrypts it before forwarding to the client. If the web server uses a cipher suite that the FortiGate does not support for re-encryption (e.g., an obsolete or non-standard cipher), the FortiGate cannot complete the SSL handshake with the client, causing certificate errors or connection failures. This is the most likely reason because the firewall policy is correct and the CA certificate is valid.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The CA certificate has expired.
Why it's wrong here
An expired CA certificate on the FortiGate would cause every HTTPS site to present an untrusted or expired certificate warning, because the FortiGate signs all inspected certificates with that CA. This scenario is site-specific (the user can access other HTTPS sites), so a global CA expiration cannot be the cause. Moreover, the error described is a handshake/cipher failure, not a certificate validity failure, which would appear as a different browser warning.
- ✓
The web server uses a cipher that the FortiGate cannot re-encrypt.
Why this is correct
When a FortiGate performs deep inspection, it terminates the client's TLS connection and then initiates a second TLS connection to the web server to re-encrypt traffic. If the web server negotiates a cipher suite, key exchange method, or TLS version that the FortiGate's SSL engine does not support or is not configured to allow, the outbound handshake fails. This manifests as a 'Cannot communicate securely' or certificate-related error for that specific server, while other sites that use supported ciphers continue to work. The administrator should review the SSL inspection profile's cipher list and ensure it aligns with the server's capabilities.
- ✗
The user's browser is outdated.
Why it's wrong here
An outdated browser can cause a variety of TLS compatibility problems, but it would not create a failure specific to the FortiGate's re-encryption to the server. The FortiGate presents its own certificate to the browser, and if the browser is too old to trust the CA, the user would see an untrusted CA error, not a cipher mismatch. Moreover, the issue is likely tied to the server's cipher selection, which the browser has no influence over; the browser is only a passive recipient of the FortiGate's certificate.
- ✗
The firewall needs a policy to allow DNS traffic.
Why it's wrong here
A missing or restrictive DNS policy would prevent the user's device from resolving the web server's hostname to an IP address, resulting in a 'server not found' or DNS resolution failure before any TCP connection is attempted. Because the user is reaching the server and receiving a certificate/handshake error, DNS resolution has already succeeded. DNS and TLS certificate validation operate at different layers, so a DNS policy cannot cause a cipher-based re-encryption failure.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.