Courseiva
Security Profiles →mediumMultiple Choice

DLP Not Detecting Credit Card Numbers Due to Encryption

An administrator configures a DLP sensor to detect credit card numbers in traffic. However, the sensor is not detecting any credit card numbers even though they are present in emails. What could be the reason?

⚠ Common exam trap

NSE4 often tests the impact of encryption on inspection; candidates may overlook that without SSL deep inspection, DLP and IPS cannot see encrypted payloads, leading to false negatives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Email traffic is encrypted and SSL deep inspection is not enabled

If a DLP sensor is configured to detect credit card numbers in emails but is not detecting them, a likely reason is that the email traffic is encrypted (e.g., via TLS) and SSL deep inspection is not enabled on the FortiGate. Without SSL deep inspection, the FortiGate cannot see the contents of encrypted emails, so the DLP sensor cannot inspect the payload for credit card numbers. Therefore, enabling SSL deep inspection would allow the DLP sensor to detect the patterns.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Email traffic is encrypted and SSL deep inspection is not enabled

    Why this is correct

    This is correct because DLP sensors operate on cleartext payloads. When email traffic is protected by TLS/SSL and SSL deep inspection is not enabled, the sensor sees only ciphertext, so any regex pattern or data-identifier match is impossible. You must enable deep inspection on the applicable firewall policy so the FortiGate can decrypt the email and feed the plaintext to the DLP sensor.

  • ✗

    The DLP sensor is applied to the wrong policy

    Why it's wrong here

    Applying the DLP sensor to the wrong policy would mean the traffic never reaches the sensor, but the symptom described is 'no detection at all' even when the intended email traffic is inspected. In practice, if the policy mismatch were the cause, you would see zero logs for that sensor on any traffic, not just encrypted email. Since the administrator specifically notes encrypted email, the more likely and fundamental barrier is lack of decryption rather than a simple policy assignment error.

  • ✗

    The credit card regular expression is incorrect

    Why it's wrong here

    An incorrect credit card regular expression could cause missed detections, but only if the DLP sensor actually receives the email content. With encryption in place and no deep inspection, the sensor processes ciphertext, so even a perfectly tuned regex would find nothing to match. The regex issue is a secondary possibility that only matters after payload decryption is resolved; it does not explain why detection fails on encrypted email while other traffic is unaffected.

  • ✗

    The DLP sensor is in 'Monitor' mode

    Why it's wrong here

    Monitor mode does not prevent DLP detection; it only changes the enforcement action from blocking to logging and alerting. The sensor still inspects the payload and matches patterns/identifiers, so if the email were decrypted, you would see detection logs even in Monitor mode. Therefore, the absence of any detections despite Monitor mode strongly points to encryption preventing payload visibility, not the sensor's action mode.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.