NSE4 Security Profiles Practice Question
An administrator wants to block all peer-to-peer (P2P) file sharing applications such as BitTorrent and eMule on the network. Which THREE steps should the administrator take?
⚠ Common exam trap
It's easy for candidates to think web filtering or antivirus can block P2P traffic, but only application control combined with deep inspection can identify and block the actual P2P protocol signatures, especially when encrypted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable deep inspection on the firewall policy to detect encrypted P2P traffic
Enabling deep inspection on the firewall policy allows the FortiGate to decrypt and inspect encrypted P2P traffic, such as BitTorrent or eMule using TLS/SSL. Without deep inspection, the firewall cannot see inside encrypted packets to identify P2P signatures, making application control ineffective for encrypted flows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a web filter profile to block P2P websites
Why it's wrong here
A web filter profile classifies URLs and HTTP/HTTPS requests, so it can block websites that host P2P software or trackers, but it cannot see the actual peer-to-peer data plane traffic that flows directly between clients. P2P clients use proprietary protocols, often over random or dynamic ports, and do not necessarily contact the blocked website after installation. Consequently, this approach stops only the download of the client, not the file-sharing transfers, so it fails to block P2P traffic.
- ✓
Enable deep inspection on the firewall policy to detect encrypted P2P traffic
Why this is correct
Deep inspection is necessary because many P2P applications encrypt their sessions with TLS/SSL, which hides protocol fingerprints from normal flow-based inspection. By acting as a man-in-the-middle and terminating the TLS connection, the FortiGate can re-inspect the decrypted payload with its application control signatures and identify the P2P protocol. Note that deep inspection alone only makes the traffic visible; it must be paired with an application control profile that blocks the P2P category to actually deny it.
- ✓
Create an application control profile with the P2P category blocked
Why this is correct
An application control profile defines the FortiGate's identification and action for various application signatures, and blocking the P2P category tells the UTM engine to drop or reset any session matching those signatures. Unlike web filtering or antivirus, application control identifies applications based on protocol behavior and packet payload, regardless of destination IP or port. This profile is the central administrative control that, once applied, enforces the P2P block.
- ✓
Apply the application control profile to a firewall policy allowing internet access
Why this is correct
A profile has no effect until it is attached to a firewall policy that passes the session; the firewall policy is the enforcement point that invokes UTM/NGFW features. Applying the application control profile to the internet-access policy ensures that all matching traffic traversing the FortiGate is inspected and the block action is triggered. Without this attachment, even with deep inspection enabled, the FortiGate would still allow the P2P sessions.
- ✗
Enable antivirus to block P2P protocols
Why it's wrong here
Antivirus protection scans files for malware signatures and scripts, but it is not an application identification engine, so it cannot classify or block protocols like BitTorrent, eMule, or uTorrent's control traffic. Although some AV signatures may catch malicious P2P payloads, the vast majority of legitimate P2P file transfers contain no malware but are still undesirable. Blocking P2P traffic is an application-control function, not an antivirus function.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.