An administrator receives alerts about a possible data breach. Sensitive data (credit card numbers) might be leaving the network via email. The admin wants to detect and block such emails. Which THREE security profiles should be combined?
The SSL deep inspection profile performs full TLS/SSL decryption and re-encryption, using a FortiGate-issued CA certificate to terminate the client connection and then open a new secure connection to the server. This decrypted traffic is then fed to other UTM profiles—email filter, DLP, antivirus—so they can see the actual payload. Without this profile, any encrypted SMTP/IMAPS/webmail traffic remains opaque, and data exfiltration could pass undetected. In the context of an email-related breach alert, this is the enabling profile that makes content inspection possible.
Why this answer
B is correct because SSL deep inspection is required to decrypt SSL/TLS-encrypted email traffic (e.g., SMTP over TLS) so that the FortiGate can inspect the content for sensitive data like credit card numbers. Without decryption, the DLP and email filter profiles cannot see the payload of encrypted emails, rendering them ineffective.
Exam trap
The trap here is that candidates often forget that encrypted email traffic (e.g., Gmail, Office 365) requires SSL deep inspection to be decrypted before DLP and email filtering can work, leading them to incorrectly omit the SSL deep inspection profile.