Application Control Not Blocking BitTorrent: SSL Deep Inspection Needed
A FortiGate administrator has configured an Application Control profile to block 'P2P' applications. However, users are still able to use BitTorrent. What is the MOST likely reason?
Quick Answer
The answer is that the firewall policy lacks SSL deep inspection, and BitTorrent is using encryption. Without deep inspection enabled for HTTPS traffic, the FortiGate’s Application Control engine cannot decrypt the encrypted payload of BitTorrent sessions, so the application signature is never matched and the traffic passes through undetected. This scenario directly tests your understanding of how Application Control relies on SSL deep inspection to see inside encrypted tunnels—a key concept on the Fortinet NSE 4 Network Security Professional NSE4 exam. A common trap is assuming that blocking the ‘P2P’ category alone is sufficient, but encrypted applications like BitTorrent will bypass detection unless you also enable deep inspection on the firewall policy. Remember the memory tip: “No decrypt, no detect—encrypted P2P slips right through.”
⚠ Common exam trap
Watch out — candidates often assume Application Control alone can block all P2P traffic, overlooking that encrypted protocols like BitTorrent require SSL deep inspection to decrypt and inspect the payload for signature matching.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall policy does not have SSL deep inspection enabled, and BitTorrent is using encryption
BitTorrent often uses encryption (e.g., MSE/PE protocol encryption) to evade detection. Without SSL deep inspection, the FortiGate cannot decrypt the traffic to inspect the application payload, so Application Control signatures for BitTorrent may not match the encrypted flows. Enabling SSL deep inspection on the firewall policy allows the FortiGate to decrypt the traffic and apply the 'Block' action effectively.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The firewall policy does not have SSL deep inspection enabled, and BitTorrent is using encryption
Why this is correct
Many P2P applications use encryption. Without deep inspection, App Control cannot see the traffic signatures.
- ✗
The Application Control profile is configured in 'Monitor' mode instead of 'Block'
Why it's wrong here
If it were in monitor mode, it would still be detected and logged, but not blocked. The question says blocked, but not working.
- ✗
The BitTorrent signatures are not included in the FortiGate firmware
Why it's wrong here
FortiGate includes many P2P signatures; updates are via FortiGuard.
- ✗
The Application Control profile is applied to the wrong direction
Why it's wrong here
Application control is bi-directional; direction is less likely the issue.
Go deeper
Related to this question
About these practice questions
One of 282 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator configures an application control profile to block 'BitTorrent'. Users are still able to download files using BitTorrent. The administrator has enabled deep inspection and the policy is set to proxy-based. What is the most likely reason the application is not being blocked?
medium- A.BitTorrent uses randomized ports that bypass application control
- B.The application control profile is not applied to the correct policy
- ✓ C.The application signatures are out of date
- D.The policy is set to flow-based instead of proxy-based
Why C: Application control uses application signatures to identify traffic. If the signatures are not up to date, new versions of BitTorrent may not be recognized. Also, if the traffic is encrypted and uses non-standard ports, application control may not detect it if the signatures are not comprehensive.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.