NSE4 Security Profiles Practice Question
When configuring SSL inspection, which type of inspection decrypts and inspects all HTTPS traffic including applications using non-standard ports?
⚠ Common exam trap
It's easy for candidates to confuse the processing mode (Flow-based vs. Proxy-based) with the actual SSL inspection method, leading candidates to incorrectly select Flow-based Inspection as a type of SSL decryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Full SSL Inspection (Deep Inspection)
Full SSL Inspection (Deep Inspection) is the correct answer because it performs a man-in-the-middle decryption and re-encryption of all HTTPS traffic, regardless of the port used. This allows the FortiGate to inspect the payload of encrypted sessions, including those on non-standard ports, for threats and policy violations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SSL Offloading
Why it's wrong here
SSL offloading is a load balancer / ADC feature that decrypts inbound HTTPS traffic to offload cryptographic processing from backend servers, then often re-encrypts it before forwarding. It is used primarily for performance and to enable HTTP-based load balancing, not for security inspection. On FortiGate, SSL inspection focuses on inspecting decrypted content for threats, which SSL offloading does not do.
- ✗
Certificate Inspection
Why it's wrong here
Certificate inspection only validates the server's SSL/TLS certificate (chain, expiry, and trust), and does not decrypt or read the session payload. It can block sessions presenting invalid certificates, but it provides no visibility into encrypted content. Consequently, it cannot detect malware, intrusion attempts, or data leakage inside the encrypted stream.
- ✓
Full SSL Inspection (Deep Inspection)
Why this is correct
Full SSL inspection (also called deep inspection) terminates the SSL/TLS connection, decrypts the traffic, applies the full security feature set (IPS, antivirus, web filtering, application control) to the plaintext, and then re-encrypts it for the destination. This gives complete visibility and control over encrypted sessions. It requires installing the FortiGate CA certificate on managed endpoints so the client trusts the re-encrypted connection.
- ✗
Flow-based Inspection
Why it's wrong here
Flow-based inspection is a traffic processing mode in FortiOS that uses an asynchronous, single-pass engine to maximize throughput with lower latency, leveraging specialized hardware acceleration. It is not a distinct type of SSL inspection; both flow-based and proxy-based modes can perform certificate or full SSL inspection. Calling it an SSL inspection type conflates the processing architecture with the decryption/inspection function.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.