Courseiva
Security ProfilesmediumMultiple ChoiceObjective-mapped

Application Control Not Blocking BitTorrent: SSL Deep Inspection Needed

A FortiGate administrator has configured an Application Control profile to block 'P2P' applications. However, users are still able to use BitTorrent. What is the MOST likely reason?

Quick Answer

The answer is that the firewall policy lacks SSL deep inspection, and BitTorrent is using encryption. Without deep inspection enabled for HTTPS traffic, the FortiGate’s Application Control engine cannot decrypt the encrypted payload of BitTorrent sessions, so the application signature is never matched and the traffic passes through undetected. This scenario directly tests your understanding of how Application Control relies on SSL deep inspection to see inside encrypted tunnels—a key concept on the Fortinet NSE 4 Network Security Professional NSE4 exam. A common trap is assuming that blocking the ‘P2P’ category alone is sufficient, but encrypted applications like BitTorrent will bypass detection unless you also enable deep inspection on the firewall policy. Remember the memory tip: “No decrypt, no detect—encrypted P2P slips right through.”

⚠ Common exam trap

Watch out — candidates often assume Application Control alone can block all P2P traffic, overlooking that encrypted protocols like BitTorrent require SSL deep inspection to decrypt and inspect the payload for signature matching.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The firewall policy does not have SSL deep inspection enabled, and BitTorrent is using encryption

BitTorrent often uses encryption (e.g., MSE/PE protocol encryption) to evade detection. Without SSL deep inspection, the FortiGate cannot decrypt the traffic to inspect the application payload, so Application Control signatures for BitTorrent may not match the encrypted flows. Enabling SSL deep inspection on the firewall policy allows the FortiGate to decrypt the traffic and apply the 'Block' action effectively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The firewall policy does not have SSL deep inspection enabled, and BitTorrent is using encryption

    Why this is correct

    Many P2P applications use encryption. Without deep inspection, App Control cannot see the traffic signatures.

  • The Application Control profile is configured in 'Monitor' mode instead of 'Block'

    Why it's wrong here

    If it were in monitor mode, it would still be detected and logged, but not blocked. The question says blocked, but not working.

  • The BitTorrent signatures are not included in the FortiGate firmware

    Why it's wrong here

    FortiGate includes many P2P signatures; updates are via FortiGuard.

  • The Application Control profile is applied to the wrong direction

    Why it's wrong here

    Application control is bi-directional; direction is less likely the issue.

About these practice questions

One of 282 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator configures an application control profile to block 'BitTorrent'. Users are still able to download files using BitTorrent. The administrator has enabled deep inspection and the policy is set to proxy-based. What is the most likely reason the application is not being blocked?

medium
  • A.BitTorrent uses randomized ports that bypass application control
  • B.The application control profile is not applied to the correct policy
  • C.The application signatures are out of date
  • D.The policy is set to flow-based instead of proxy-based

Why C: Application control uses application signatures to identify traffic. If the signatures are not up to date, new versions of BitTorrent may not be recognized. Also, if the traffic is encrypted and uses non-standard ports, application control may not detect it if the signatures are not comprehensive.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.