Courseiva
Security Profiles →easyMultiple Choice

NSE4 Security Profiles Practice Question

When configuring SSL inspection, which type of inspection decrypts and inspects all HTTPS traffic including applications using non-standard ports?

⚠ Common exam trap

It's easy for candidates to confuse the processing mode (Flow-based vs. Proxy-based) with the actual SSL inspection method, leading candidates to incorrectly select Flow-based Inspection as a type of SSL decryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Full SSL Inspection (Deep Inspection)

Full SSL Inspection (Deep Inspection) is the correct answer because it performs a man-in-the-middle decryption and re-encryption of all HTTPS traffic, regardless of the port used. This allows the FortiGate to inspect the payload of encrypted sessions, including those on non-standard ports, for threats and policy violations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SSL Offloading

    Why it's wrong here

    SSL offloading is a load balancer / ADC feature that decrypts inbound HTTPS traffic to offload cryptographic processing from backend servers, then often re-encrypts it before forwarding. It is used primarily for performance and to enable HTTP-based load balancing, not for security inspection. On FortiGate, SSL inspection focuses on inspecting decrypted content for threats, which SSL offloading does not do.

  • ✗

    Certificate Inspection

    Why it's wrong here

    Certificate inspection only validates the server's SSL/TLS certificate (chain, expiry, and trust), and does not decrypt or read the session payload. It can block sessions presenting invalid certificates, but it provides no visibility into encrypted content. Consequently, it cannot detect malware, intrusion attempts, or data leakage inside the encrypted stream.

  • ✓

    Full SSL Inspection (Deep Inspection)

    Why this is correct

    Full SSL inspection (also called deep inspection) terminates the SSL/TLS connection, decrypts the traffic, applies the full security feature set (IPS, antivirus, web filtering, application control) to the plaintext, and then re-encrypts it for the destination. This gives complete visibility and control over encrypted sessions. It requires installing the FortiGate CA certificate on managed endpoints so the client trusts the re-encrypted connection.

  • ✗

    Flow-based Inspection

    Why it's wrong here

    Flow-based inspection is a traffic processing mode in FortiOS that uses an asynchronous, single-pass engine to maximize throughput with lower latency, leveraging specialized hardware acceleration. It is not a distinct type of SSL inspection; both flow-based and proxy-based modes can perform certificate or full SSL inspection. Calling it an SSL inspection type conflates the processing architecture with the decryption/inspection function.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.