Courseiva
Security Profiles →mediumMultiple Select

NSE4 Security Profiles Practice Question

An administrator configures a DLP profile to detect Social Security numbers in outbound traffic. The profile is applied to an outbound HTTP policy. Which TWO additional configurations are necessary for the DLP to inspect HTTPS traffic?

⚠ Common exam trap

Watch out — candidates often confuse SSL exemptions (which bypass inspection) with SSL deep inspection (which enables inspection), or assume that proxy-based mode alone is sufficient for HTTPS DLP, ignoring the mandatory decryption step.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable SSL/TLS deep inspection on the firewall policy

DLP inspection of HTTPS traffic requires the firewall to decrypt the encrypted payload. Enabling SSL/TLS deep inspection on the firewall policy allows FortiGate to perform man-in-the-middle decryption, re-encrypt, and then inspect the decrypted content for sensitive data like Social Security numbers. Without deep inspection, the DLP engine sees only encrypted traffic and cannot match patterns.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the firewall policy inspection mode to proxy-based

    Why it's wrong here

    Changing the firewall policy inspection mode to proxy-based alone does not enable DLP. FortiGate DLP can work with both proxy-based and flow-based inspection, but regardless of mode, the traffic must first be decrypted via SSL/TLS deep inspection; otherwise the DLP engine only sees the encrypted payload. Proxy-based mode is a prerequisite for some advanced features but is neither necessary for DLP nor sufficient to inspect HTTPS content.

  • ✗

    Add an SSL exemption for the destination servers

    Why it's wrong here

    Adding an SSL exemption for the destination servers tells FortiGate to skip decryption for those connections. Since DLP relies on reading plaintext after TLS termination, exempting the servers means the policy will pass encrypted traffic through without inspection, so the DLP sensor will never see the social security numbers. This is the opposite of what is required for DLP to function on HTTPS traffic.

  • ✓

    Enable SSL/TLS deep inspection on the firewall policy

    Why this is correct

    SSL/TLS deep inspection is mandatory for DLP to detect sensitive data in HTTPS traffic. When enabled, FortiGate terminates the TLS session using its certificate as a trusted CA, decrypts the payload, and hands the plaintext to security profiles—including the DLP sensor—for inspection. Without deep inspection, only non-encrypted traffic or traffic subject to certificate inspection (which examines only certificate metadata) can be evaluated, making DLP blind to the content of an encrypted web session.

  • ✓

    Create a DLP sensor with the correct pattern and apply it to the policy

    Why this is correct

    Creating a DLP sensor with the correct pattern and applying it to the firewall policy is a required step because DLP works only when a sensor is explicitly referenced in the policy. The sensor contains the regular expressions or data identifiers that match social security numbers, and the policy must associate that sensor with the flows to be scanned. Even with deep inspection enabled, a missing or misapplied sensor means no DLP detection occurs.

  • ✗

    Configure a web filter profile to allow the traffic

    Why it's wrong here

    Configuring a web filter profile to allow traffic is not connected to how DLP inspects content; web filtering is a separate category that controls URL access, not data content. While a web filter profile could block a site before the DLP sensor sees it, simply allowing traffic does not enable or improve DLP scanning. DLP activation depends solely on having an appropriate DLP sensor applied to the policy and, for encrypted traffic, deep inspection.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.