Courseiva
Security Profiles →mediumMultiple Choice

NSE4 Security Profiles Practice Question

An administrator needs to ensure that users cannot upload files to a specific cloud storage service via HTTPS, while still allowing them to view and download files from the same service. The FortiGate is currently performing SSL deep inspection on all outbound HTTPS traffic. Which security profile should the administrator configure to meet this requirement?

⚠ Common exam trap

The trap here is assuming that web filtering or DLP can control application-specific actions like upload versus download within an allowed application.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Application control

Application control is designed to identify applications and their actions, even within encrypted traffic when SSL deep inspection is active. It can enforce policies that distinguish between upload and download actions for cloud storage apps. This allows the administrator to block uploads while permitting viewing and downloading, exactly as required.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Antivirus

    Why it's wrong here

    Antivirus scans files for malware but does not control application actions such as upload or download. It cannot enforce a policy that blocks only uploads to a cloud storage service. Thus it is not the appropriate profile for this scenario.

  • ✗

    Data loss prevention (DLP)

    Why it's wrong here

    DLP inspects content for sensitive data patterns and can block based on file type or content, but it does not natively distinguish upload from download actions for a specific cloud application. It could block files containing certain data, but not simply all uploads to that service.

  • ✓

    Application control

    Why this is correct

    Application control can identify the cloud storage application and apply per-application actions. With SSL deep inspection enabled, it can see inside HTTPS and block only the upload action for that application while allowing download. This meets the requirement precisely without affecting other traffic.

  • ✗

    Web filter

    Why it's wrong here

    Web filter operates on URLs and categories, not on application actions like upload versus download. It can block the entire site or category, but cannot selectively permit viewing and downloading while blocking uploads. Therefore it does not satisfy the granular requirement.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.