NSE4 Security Profiles Practice Question
An administrator needs to ensure that users cannot upload files to a specific cloud storage service via HTTPS, while still allowing them to view and download files from the same service. The FortiGate is currently performing SSL deep inspection on all outbound HTTPS traffic. Which security profile should the administrator configure to meet this requirement?
⚠ Common exam trap
The trap here is assuming that web filtering or DLP can control application-specific actions like upload versus download within an allowed application.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Application control
Application control is designed to identify applications and their actions, even within encrypted traffic when SSL deep inspection is active. It can enforce policies that distinguish between upload and download actions for cloud storage apps. This allows the administrator to block uploads while permitting viewing and downloading, exactly as required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Antivirus
Why it's wrong here
Antivirus scans files for malware but does not control application actions such as upload or download. It cannot enforce a policy that blocks only uploads to a cloud storage service. Thus it is not the appropriate profile for this scenario.
- ✗
Data loss prevention (DLP)
Why it's wrong here
DLP inspects content for sensitive data patterns and can block based on file type or content, but it does not natively distinguish upload from download actions for a specific cloud application. It could block files containing certain data, but not simply all uploads to that service.
- ✓
Application control
Why this is correct
Application control can identify the cloud storage application and apply per-application actions. With SSL deep inspection enabled, it can see inside HTTPS and block only the upload action for that application while allowing download. This meets the requirement precisely without affecting other traffic.
- ✗
Web filter
Why it's wrong here
Web filter operates on URLs and categories, not on application actions like upload versus download. It can block the entire site or category, but cannot selectively permit viewing and downloading while blocking uploads. Therefore it does not satisfy the granular requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.