NSE4 Security Profiles Practice Question
An administrator needs to ensure that all HTTPS traffic to a critical server is inspected by the IPS. The server uses a valid certificate from a public CA. Which THREE steps are required to achieve this?
⚠ Common exam trap
NSE4 often tests the misconception that uploading the server's certificate is required for deep inspection, when actually the FortiGate's CA certificate must be trusted by clients.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply an IPS profile to the same firewall policy
Option D is correct because SSL deep inspection must be enabled on the firewall policy so the FortiGate decrypts the HTTPS session and can pass the plaintext to the IPS engine; without it, the IPS only sees encrypted traffic. Option A is correct because the IPS profile must be attached to that same firewall policy that carries the inspected traffic, otherwise the decrypted stream is never scanned by the IPS sensors. Option C is correct because deep inspection causes the FortiGate to re-sign the server's certificate with its own CA (the FortiGate's local/protection CA), so client browsers must trust that CA certificate to avoid certificate warnings and failed connections. Option B is wrong because 'Deep Inspection' is a setting of the SSL/SSH inspection profile, not the Antivirus profile, and antivirus is not what performs IPS inspection. Option E is wrong because the server already presents a valid public CA certificate; the FortiGate does not need the server's certificate uploaded to perform deep inspection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Apply an IPS profile to the same firewall policy
Why this is correct
This is necessary because even with SSL deep inspection enabled, the decrypted traffic is only inspected if an IPS profile is attached to the policy. The IPS engine then examines the plaintext HTTP/HTTPS payloads for signatures, vulnerabilities, and exploits. Without an IPS profile, deep inspection alone just decrypts/encrypts but doesn't provide intrusion prevention.
- ✗
Set the Antivirus profile to 'Deep Inspection'
Why it's wrong here
Antivirus profiles on FortiGate don't have a 'Deep Inspection' mode as such; they have 'Inspection Mode' options like 'Proxy-based' or 'Flow-based' but that's not the same as SSL deep inspection. The actual deep inspection feature is enabled on the firewall policy (or a separate SSL/SSH inspection profile) and applies to the protocol-level decryption. Antivirus profiles work with the decrypted traffic but don't control whether traffic is decrypted.
- ✓
Install the FortiGate's CA certificate on client browsers
Why this is correct
When FortiGate performs SSL deep inspection, it presents a certificate signed by its own CA. To avoid TLS warnings and ensure seamless inspection, clients must trust that root CA. Deploying the FortiGate CA to the browser/OS trust store is a standard operational step for explicit or transparent proxy inspection. Without it, users see certificate errors which can break connectivity or cause them to bypass.
- ✓
Enable SSL deep inspection on the firewall policy
Why this is correct
This is the core required action. SSL deep inspection (via an SSL/SSH inspection profile) enables the firewall to terminate the TLS handshake, re-encrypt the session using a FortiGate-generated certificate, and then forward the decrypted traffic to subsequent security profiles like IPS. Without enabling this on the policy (or the associated inspection profile), IPS cannot inspect encrypted content because traffic remains opaque to the FortiGate.
- ✗
Upload the server's certificate to the FortiGate
Why it's wrong here
In standard SSL deep inspection (not full certificate authentication), the FortiGate does not need the server's private key; it dynamically generates a new certificate signed by its own CA for each site. Uploading the server's certificate is not required because the FortiGate is not impersonating the server with the original certificate; it creates a new one on the fly. Even if you upload it, it would not help the firewall decrypt traffic without the private key, and the purpose is to inspect, not to use the original cert.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.