Courseiva
Security Profiles →hardMultiple Select

NSE4 Security Profiles Practice Question

An administrator needs to ensure that all HTTPS traffic to a critical server is inspected by the IPS. The server uses a valid certificate from a public CA. Which THREE steps are required to achieve this?

⚠ Common exam trap

NSE4 often tests the misconception that uploading the server's certificate is required for deep inspection, when actually the FortiGate's CA certificate must be trusted by clients.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply an IPS profile to the same firewall policy

Option D is correct because SSL deep inspection must be enabled on the firewall policy so the FortiGate decrypts the HTTPS session and can pass the plaintext to the IPS engine; without it, the IPS only sees encrypted traffic. Option A is correct because the IPS profile must be attached to that same firewall policy that carries the inspected traffic, otherwise the decrypted stream is never scanned by the IPS sensors. Option C is correct because deep inspection causes the FortiGate to re-sign the server's certificate with its own CA (the FortiGate's local/protection CA), so client browsers must trust that CA certificate to avoid certificate warnings and failed connections. Option B is wrong because 'Deep Inspection' is a setting of the SSL/SSH inspection profile, not the Antivirus profile, and antivirus is not what performs IPS inspection. Option E is wrong because the server already presents a valid public CA certificate; the FortiGate does not need the server's certificate uploaded to perform deep inspection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Apply an IPS profile to the same firewall policy

    Why this is correct

    This is necessary because even with SSL deep inspection enabled, the decrypted traffic is only inspected if an IPS profile is attached to the policy. The IPS engine then examines the plaintext HTTP/HTTPS payloads for signatures, vulnerabilities, and exploits. Without an IPS profile, deep inspection alone just decrypts/encrypts but doesn't provide intrusion prevention.

  • ✗

    Set the Antivirus profile to 'Deep Inspection'

    Why it's wrong here

    Antivirus profiles on FortiGate don't have a 'Deep Inspection' mode as such; they have 'Inspection Mode' options like 'Proxy-based' or 'Flow-based' but that's not the same as SSL deep inspection. The actual deep inspection feature is enabled on the firewall policy (or a separate SSL/SSH inspection profile) and applies to the protocol-level decryption. Antivirus profiles work with the decrypted traffic but don't control whether traffic is decrypted.

  • ✓

    Install the FortiGate's CA certificate on client browsers

    Why this is correct

    When FortiGate performs SSL deep inspection, it presents a certificate signed by its own CA. To avoid TLS warnings and ensure seamless inspection, clients must trust that root CA. Deploying the FortiGate CA to the browser/OS trust store is a standard operational step for explicit or transparent proxy inspection. Without it, users see certificate errors which can break connectivity or cause them to bypass.

  • ✓

    Enable SSL deep inspection on the firewall policy

    Why this is correct

    This is the core required action. SSL deep inspection (via an SSL/SSH inspection profile) enables the firewall to terminate the TLS handshake, re-encrypt the session using a FortiGate-generated certificate, and then forward the decrypted traffic to subsequent security profiles like IPS. Without enabling this on the policy (or the associated inspection profile), IPS cannot inspect encrypted content because traffic remains opaque to the FortiGate.

  • ✗

    Upload the server's certificate to the FortiGate

    Why it's wrong here

    In standard SSL deep inspection (not full certificate authentication), the FortiGate does not need the server's private key; it dynamically generates a new certificate signed by its own CA for each site. Uploading the server's certificate is not required because the FortiGate is not impersonating the server with the original certificate; it creates a new one on the fly. Even if you upload it, it would not help the firewall decrypt traffic without the private key, and the purpose is to inspect, not to use the original cert.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.