Courseiva
Security ProfileshardMultiple ChoiceObjective-mapped

Application Control Not Blocking Facebook Without SSL Deep Inspection

An administrator configures an application control profile to block 'Facebook' and 'Twitter' using application signatures. Users can still access Facebook via HTTPS. The firewall policy has application control enabled and SSL deep inspection is not configured. Why is Facebook not blocked?

Quick Answer

The answer is that without SSL deep inspection, FortiGate cannot inspect encrypted HTTPS traffic to match application signatures. This is because application control relies on analyzing the unencrypted payload of network traffic to identify applications like Facebook or Twitter, but HTTPS encrypts the entire session, including the application-layer data. On the Fortinet NSE 4 Network Security Professional exam, this scenario tests your understanding that application control alone is insufficient for blocking encrypted applications—decryption via SSL deep inspection is a prerequisite. A common trap is assuming application signatures can magically see through encryption, but they cannot; the firewall only sees the encrypted tunnel, not the content inside. Remember the memory tip: “No decrypt, no detect”—if the traffic is encrypted and deep inspection is off, application control is blind to the application inside.

⚠ Common exam trap

Test-takers frequently assume application control can block any application regardless of encryption, overlooking the fundamental requirement for SSL deep inspection to inspect HTTPS traffic at the application layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

HTTPS traffic is encrypted and cannot be inspected without SSL deep inspection

Without SSL deep inspection, the FortiGate cannot decrypt HTTPS traffic to inspect the application-layer payload. Application control relies on inspecting unencrypted traffic or using SSL inspection to identify applications within encrypted sessions. Since Facebook uses HTTPS, the encrypted traffic passes through without being matched against the application signature, so the block action is not enforced.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The application signature for Facebook is not updated

    Why it's wrong here

    Even if updated, cannot inspect encrypted traffic.

  • The application control profile is configured in monitor-only mode

    Why it's wrong here

    Monitor mode would log but not block; the question says block is configured.

  • HTTPS traffic is encrypted and cannot be inspected without SSL deep inspection

    Why this is correct

    Application signatures rely on payload; encryption hides that.

  • Facebook uses a non-standard port that application control does not monitor

    Why it's wrong here

    Facebook typically uses port 443, which is monitored.

About these practice questions

One of 282 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator configures an application control profile to block social media applications. Users can still access Facebook and Twitter via web browsers. What is the most likely reason?

medium
  • A.The application signatures for Facebook and Twitter are not up to date
  • B.The firewall policy has SSL/SSH inspection set to 'certificate-inspection' instead of 'deep-inspection'
  • C.The application control profile is set to 'monitor' instead of 'block'
  • D.The firewall policy is configured with flow-based inspection

Why B: When SSL/SSH inspection is set to 'certificate-inspection' (default), the FortiGate only inspects the certificate handshake and cannot decrypt the encrypted application-layer traffic. Social media applications like Facebook and Twitter use HTTPS, so without deep inspection (full decryption), the application control profile cannot identify and block the application signatures within the encrypted payload. Deep inspection is required to decrypt the traffic and allow the IPS engine to match application signatures.

Variation 2. A network administrator configures an application control profile to block social media applications. Users can still access Facebook through a web browser. What is the MOST likely reason?

medium
  • A.The application signatures are outdated
  • B.Application control is not enabled for HTTPS traffic without deep inspection
  • C.The firewall policy is in proxy-based mode
  • D.The application control profile is not applied to the correct policy

Why B: Application control relies on deep inspection (SSL/TLS decryption) to identify applications within encrypted HTTPS traffic. Without deep inspection enabled, the FortiGate can only see the encrypted tunnel and cannot inspect the payload to determine that the traffic is Facebook, even if the application control profile is correctly applied. Option B is correct because HTTPS traffic must be decrypted via deep inspection for application control to function.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.