An administrator has configured the policy shown in the exhibit. Traffic to the web server at 10.0.1.10 over HTTPS is allowed, but users complain that they cannot access the web server's login page. The IPS sensor 'High_Security_Sensor' has a signature that blocks SQL injection attempts. The application list 'Block_Social_Media' blocks Facebook and Twitter. What is the most likely cause of the issue?
The application control profile is the only profile configured in the policy that can identify and block specific web applications by their signatures, even when the underlying HTTP/HTTPS service is valid. When a user attempts to access the login page, the FortiGate can classify the traffic as a known application and apply the profile's 'block' action, denying the request. This is a common cause of access failure when the base policy action is accept and HTTPS is correctly defined.
Why this answer
The policy explicitly allows HTTPS traffic to 10.0.1.10, but the application control profile 'Block_Social_Media' is applied. This profile blocks Facebook and Twitter, which are web-based applications. If the web server's login page is served over HTTPS and is incorrectly classified by the FortiGate as a social media application (e.g., due to shared CDN or similar traffic patterns), the application control profile will block it, preventing user access despite the firewall policy allowing the service.
Exam trap
The trap here is that candidates assume the IPS sensor is the cause of the block, but the question specifies the IPS sensor only blocks SQL injection attempts, not login pages, while the application control profile explicitly blocks social media applications that could be misclassifying the web server's traffic.
How to eliminate wrong answers
Option A is wrong because the IPS sensor 'High_Security_Sensor' has a signature that blocks SQL injection attempts, not login pages; a false positive for SQL injection would block specific HTTP requests containing malicious patterns, not the entire login page. Option B is wrong because the exhibit shows the policy action as 'accept', and the question states traffic is allowed; a 'deny' action would block all traffic, not just the login page. Option C is wrong because HTTPS is a well-defined service (TCP/443) and the policy explicitly allows it; if the service were misdefined, all HTTPS traffic would be blocked, not just the login page.