Courseiva
Security Profiles →mediumMultiple Choice

Why Application Control Fails on HTTPS Traffic Without SSL Decryption

An organization uses Application Control to allow only business-critical applications and block social media. The administrator has configured the profile to block Facebook and Twitter, but users can still access Facebook. The firewall policy applies the profile correctly. What is the most likely cause?

⚠ Common exam trap

A common mix-up: candidates assume application control works on encrypted traffic by default, but FortiGate requires explicit SSL inspection to decrypt and identify HTTPS applications like Facebook.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSL inspection is not enabled on the firewall policy.

Application Control relies on SSL inspection to identify applications like Facebook that use HTTPS. Without SSL inspection enabled on the firewall policy, FortiGate can only see encrypted traffic as generic SSL/TLS flows and cannot match the application signatures for Facebook. Enabling SSL inspection (deep inspection or certificate-based inspection) allows the FortiGate to decrypt the traffic and apply the application control profile correctly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The application control profile is applied to the wrong direction.

    Why it's wrong here

    Application control policies on FortiGate are direction-aware in the sense that they are referenced from an explicit or implicit firewall policy that matches a specific source and destination zone. While a profile applied to the wrong policy (e.g., the inbound rather than outbound policy) would indeed prevent inspection of user web traffic, the scenario explicitly states the profile is applied correctly. Thus, direction is not the misconfiguration causing Facebook to be allowed.

  • ✗

    Facebook is not included in the default application signatures.

    Why it's wrong here

    FortiGate’s IPS/Application Control database ships with thousands of default application signatures, and popular social media sites like Facebook have been included for years. These signatures are maintained through regular vulnerability and application updates from FortiGuard, so the absence of a Facebook signature is not a plausible cause. Even if a new variant appears, the default signature set already covers the base Facebook application, so this option is incorrect.

  • ✓

    SSL inspection is not enabled on the firewall policy.

    Why this is correct

    Without SSL deep inspection, HTTPS sessions appear as opaque flows to the security engine, allowing FortiGate to see only the initial TLS ClientHello (including SNI) and encrypted data afterward. Application control cannot read the HTTP Host header, cookies, or URI paths needed to confidently match the traffic to the 'Facebook' application, so HTTPS requests like news feed or chat are not blocked. The correct remedy is to enable an SSL/SSH inspection profile (typically 'deep-inspection') on the policy and install the FortiGate CA on client devices, allowing the Security Processing Unit to decrypt, inspect, and re-encrypt the session. This is why the answer identifies missing SSL inspection as the root cause.

  • ✗

    The FortiGate is in flow-based inspection mode.

    Why it's wrong here

    Flow-based inspection is not a limitation for application control; in fact, FortiGate’s flow-based mode is specifically optimized to use CP8 or NP7 acceleration and is fully capable of matching application signatures on the first packet. Application control works in both flow-based and proxy-based inspection modes, since it relies on the same signature database and heuristics. Therefore, choosing flow-based mode does not prevent Facebook from being detected; it merely changes how the traffic is processed and accelerated.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.