NSE4 Security Profiles Practice Question
An administrator is troubleshooting why an application control profile is not detecting a custom application that uses a non-standard port. The administrator wants to ensure the application is properly identified. Which THREE steps should the administrator take? (Choose three.)
⚠ Common exam trap
The trap is focusing on enforcement actions (like block) or inspection modes instead of the necessary steps for detection: custom signatures, correct policy application, and SSL inspection for encrypted traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a custom application signature based on the traffic pattern
Option B is correct because application control can only identify a custom application on a non-standard port if a custom application signature is created that matches its traffic pattern, since the default signature database will not recognize it. Option D is correct because an application control profile only takes effect when it is attached to the firewall policy that handles the traffic; if it is applied to the wrong policy, the custom application will never be inspected or detected. Option E is correct because if the custom application's traffic is encrypted with SSL/TLS, the firewall cannot see the application-layer data needed for identification unless SSL deep inspection is enabled to decrypt and inspect it. Option A is incorrect because setting the action to 'block' only controls what happens after identification and does nothing to help the firewall recognize the application. Option C is incorrect because disabling flow-based inspection and using proxy-based only is not a required step for identifying a custom application and may not even be supported or desirable in all deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the application control action to 'block' for the application
Why it's wrong here
Setting the application control action to 'block' does not improve detection; action and detection are independent stages. If the application is not identified because its signature is missing or the traffic is encrypted, the block action will never trigger. Detection requires either a matching built-in signature, a custom signature, or sufficient visibility into the payload. Reconfiguring the action merely changes the response after identification, so it would not resolve the detection failure.
- ✓
Add a custom application signature based on the traffic pattern
Why this is correct
If the application is not covered by any built-in FortiGuard signature, the administrator should create a custom application signature based on the traffic's unique pattern. On FortiGate, this is done by defining a custom signature using attributes such as protocol, port, IP, or content-matching criteria in the application control profile. This directly adds detection capability for the unrecognized application, allowing it to be identified and controlled. Without a signature, the application remains invisible to the security inspection.
- ✗
Disable flow-based inspection and use proxy-based only
Why it's wrong here
Disabling flow-based inspection in favor of proxy-based mode is not a standard troubleshooting step because application control is available in both inspection modes. Both modes rely on the same application signature database; flow-based simply uses a single-pass, performance-optimized path, while proxy-based performs full protocol decoding. If the root cause is a missing signature or lack of deep inspection, switching modes will not make the application detectable. The mode affects how traffic is processed, not the signature coverage or detection logic.
- ✓
Ensure the application control profile is applied to the correct firewall policy
Why this is correct
A common reason for application control failing to detect traffic is that the application control profile is not attached to the firewall policy that actually handles the traffic. The administrator must verify that the correct policy, in the correct order, has the profile applied, and that other policies are not matching the traffic first. If the profile is applied to a different policy — or to none at all — the FortiGate will allow or process the traffic without any application identification. Confirming policy binding is a first-line check before modifying signatures or inspection modes.
- ✓
Enable SSL deep inspection if the application uses encryption
Why this is correct
If the application communicates over an encrypted channel such as HTTPS or SSL/TLS, the FortiGate cannot inspect the payload for matching signatures unless SSL deep inspection is enabled. Application control on encrypted traffic can only rely on limited metadata like SNI, IP addresses, or ports, which is often insufficient to identify the specific application. Enabling a deep inspection profile that decrypts the traffic allows the FortiGate to perform signature matching on the decrypted content. This is a necessary prerequisite for detecting many modern applications that use encryption.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.