Courseiva
Security Profiles →hardMultiple Choice

NSE4 Security Profiles Practice Question

An administrator notices that traffic to a specific HTTPS website is being blocked. The FortiGate has SSL inspection enabled, and the web filter profile is set to monitor all categories. The URL is not in any blocked category. What should the administrator check next?

⚠ Common exam trap

Many candidates assume HTTPS blocking is always due to web filter categories or inspection depth, overlooking that certificate revocation checks in the SSL inspection profile can independently block traffic even when the URL is allowed by the web filter.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the SSL/SSH inspection profile's certificate revocation check settings.

When SSL inspection is enabled and a specific HTTPS site is blocked despite not being in a blocked category, the issue often lies in the SSL/SSH inspection profile's certificate revocation check. If the FortiGate cannot verify the server's certificate revocation status (e.g., via OCSP or CRL), it may block the connection as a security precaution, even if the web filter category allows the URL. Option B directly addresses this by suggesting a review of the revocation check settings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Check if the SSL inspection policy is using certificate inspection instead of full SSL inspection.

    Why it's wrong here

    Certificate inspection (sometimes called SNI-based inspection) only reads the Server Name Indication and the certificate metadata, then forwards the HTTPS session without decrypting the payload. Because it does not perform a full handshake or decrypt the flow, it cannot trigger a hard block based on certificate revocation status; it would allow the traffic to pass. Therefore, checking whether the profile uses certificate vs. full SSL inspection would not explain a revocation-related block for a specific HTTPS site.

  • ✓

    Review the SSL/SSH inspection profile's certificate revocation check settings.

    Why this is correct

    The SSL/SSH inspection profile contains certificate revocation check settings that validate the server certificate against Certificate Revocation Lists (CRL) and/or OCSP responders. If the revocation check is enabled and the site's certificate is revoked, the FortiGate will refuse to establish the TLS connection and block the HTTPS session, even if the URL category is allowed. This directly explains why traffic to a specific HTTPS site fails while other sites still work, making it the correct first step to review. Additionally, strict blocking can also occur if the OCSP responder is unreachable, so reviewing these settings is essential.

  • ✗

    Ensure that the FortiGate has the latest web filter database.

    Why it's wrong here

    An outdated web filter database may cause a URL to be miscategorized, but the administrator already confirmed that the URL is not in a blocked web filter category. Updating the database would therefore not change the blocking behavior, because the category has already been ruled out as the cause. The reported symptom is a specific HTTPS site failing, which points to the SSL/TLS inspection layer rather than to URL categorization or rating database freshness.

  • ✗

    Verify that the web filter has the correct rating for the URL.

    Why it's wrong here

    The administrator explicitly noted that the URL is not in a blocked web filter category, so re-verifying the rating would only duplicate an already completed check. If the URL was not categorized as blocked, the web filter will allow the HTTP-level request; the block must be happening earlier in the TLS handshake or during certificate validation. This is why examining the SSL/SSH inspection profile's certificate revocation settings is more targeted than rechecking the web filter rating.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.