Courseiva
Security Profiles →hardMultiple Select

NSE4 Security Profiles Practice Question

An administrator is troubleshooting why an application control profile is not detecting a custom application that uses a non-standard port. The administrator wants to ensure the application is properly identified. Which THREE steps should the administrator take? (Choose three.)

⚠ Common exam trap

The trap is focusing on enforcement actions (like block) or inspection modes instead of the necessary steps for detection: custom signatures, correct policy application, and SSL inspection for encrypted traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a custom application signature based on the traffic pattern

Option B is correct because application control can only identify a custom application on a non-standard port if a custom application signature is created that matches its traffic pattern, since the default signature database will not recognize it. Option D is correct because an application control profile only takes effect when it is attached to the firewall policy that handles the traffic; if it is applied to the wrong policy, the custom application will never be inspected or detected. Option E is correct because if the custom application's traffic is encrypted with SSL/TLS, the firewall cannot see the application-layer data needed for identification unless SSL deep inspection is enabled to decrypt and inspect it. Option A is incorrect because setting the action to 'block' only controls what happens after identification and does nothing to help the firewall recognize the application. Option C is incorrect because disabling flow-based inspection and using proxy-based only is not a required step for identifying a custom application and may not even be supported or desirable in all deployments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the application control action to 'block' for the application

    Why it's wrong here

    Setting the application control action to 'block' does not improve detection; action and detection are independent stages. If the application is not identified because its signature is missing or the traffic is encrypted, the block action will never trigger. Detection requires either a matching built-in signature, a custom signature, or sufficient visibility into the payload. Reconfiguring the action merely changes the response after identification, so it would not resolve the detection failure.

  • ✓

    Add a custom application signature based on the traffic pattern

    Why this is correct

    If the application is not covered by any built-in FortiGuard signature, the administrator should create a custom application signature based on the traffic's unique pattern. On FortiGate, this is done by defining a custom signature using attributes such as protocol, port, IP, or content-matching criteria in the application control profile. This directly adds detection capability for the unrecognized application, allowing it to be identified and controlled. Without a signature, the application remains invisible to the security inspection.

  • ✗

    Disable flow-based inspection and use proxy-based only

    Why it's wrong here

    Disabling flow-based inspection in favor of proxy-based mode is not a standard troubleshooting step because application control is available in both inspection modes. Both modes rely on the same application signature database; flow-based simply uses a single-pass, performance-optimized path, while proxy-based performs full protocol decoding. If the root cause is a missing signature or lack of deep inspection, switching modes will not make the application detectable. The mode affects how traffic is processed, not the signature coverage or detection logic.

  • ✓

    Ensure the application control profile is applied to the correct firewall policy

    Why this is correct

    A common reason for application control failing to detect traffic is that the application control profile is not attached to the firewall policy that actually handles the traffic. The administrator must verify that the correct policy, in the correct order, has the profile applied, and that other policies are not matching the traffic first. If the profile is applied to a different policy — or to none at all — the FortiGate will allow or process the traffic without any application identification. Confirming policy binding is a first-line check before modifying signatures or inspection modes.

  • ✓

    Enable SSL deep inspection if the application uses encryption

    Why this is correct

    If the application communicates over an encrypted channel such as HTTPS or SSL/TLS, the FortiGate cannot inspect the payload for matching signatures unless SSL deep inspection is enabled. Application control on encrypted traffic can only rely on limited metadata like SNI, IP addresses, or ports, which is often insufficient to identify the specific application. Enabling a deep inspection profile that decrypts the traffic allows the FortiGate to perform signature matching on the decrypted content. This is a necessary prerequisite for detecting many modern applications that use encryption.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.