DLP Not Detecting Credit Card Numbers Due to Encryption
An administrator configures a DLP sensor to detect credit card numbers in traffic. However, the sensor is not detecting any credit card numbers even though they are present in emails. What could be the reason?
⚠ Common exam trap
NSE4 often tests the impact of encryption on inspection; candidates may overlook that without SSL deep inspection, DLP and IPS cannot see encrypted payloads, leading to false negatives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Email traffic is encrypted and SSL deep inspection is not enabled
If a DLP sensor is configured to detect credit card numbers in emails but is not detecting them, a likely reason is that the email traffic is encrypted (e.g., via TLS) and SSL deep inspection is not enabled on the FortiGate. Without SSL deep inspection, the FortiGate cannot see the contents of encrypted emails, so the DLP sensor cannot inspect the payload for credit card numbers. Therefore, enabling SSL deep inspection would allow the DLP sensor to detect the patterns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Email traffic is encrypted and SSL deep inspection is not enabled
Why this is correct
This is correct because DLP sensors operate on cleartext payloads. When email traffic is protected by TLS/SSL and SSL deep inspection is not enabled, the sensor sees only ciphertext, so any regex pattern or data-identifier match is impossible. You must enable deep inspection on the applicable firewall policy so the FortiGate can decrypt the email and feed the plaintext to the DLP sensor.
- ✗
The DLP sensor is applied to the wrong policy
Why it's wrong here
Applying the DLP sensor to the wrong policy would mean the traffic never reaches the sensor, but the symptom described is 'no detection at all' even when the intended email traffic is inspected. In practice, if the policy mismatch were the cause, you would see zero logs for that sensor on any traffic, not just encrypted email. Since the administrator specifically notes encrypted email, the more likely and fundamental barrier is lack of decryption rather than a simple policy assignment error.
- ✗
The credit card regular expression is incorrect
Why it's wrong here
An incorrect credit card regular expression could cause missed detections, but only if the DLP sensor actually receives the email content. With encryption in place and no deep inspection, the sensor processes ciphertext, so even a perfectly tuned regex would find nothing to match. The regex issue is a secondary possibility that only matters after payload decryption is resolved; it does not explain why detection fails on encrypted email while other traffic is unaffected.
- ✗
The DLP sensor is in 'Monitor' mode
Why it's wrong here
Monitor mode does not prevent DLP detection; it only changes the enforcement action from blocking to logging and alerting. The sensor still inspects the payload and matches patterns/identifiers, so if the email were decrypted, you would see detection logs even in Monitor mode. Therefore, the absence of any detections despite Monitor mode strongly points to encryption preventing payload visibility, not the sensor's action mode.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.