NSE4 Security Profiles Practice Question
Which SSL/TLS inspection mode only validates the server certificate without decrypting the traffic?
⚠ Common exam trap
A common mix-up: candidates confuse 'certificate inspection' with 'deep inspection' because both involve SSL/TLS, but deep inspection requires decryption while certificate inspection does not.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Certificate inspection
Certificate inspection is the correct answer because it validates the server certificate's authenticity and expiration without decrypting the traffic. This mode checks the certificate chain and revocation status using OCSP or CRLs, but the encrypted payload remains untouched, preserving end-to-end encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deep inspection
Why it's wrong here
Deep inspection is wrong because it goes far beyond certificate validation: it fully decrypts the SSL/TLS session, inspects the plaintext application traffic against all configured security profiles (IPS, antivirus, web filtering), and then re-encrypts the traffic before forwarding it. This mode requires installing a Fortinet CA on clients to perform man-in-the-middle decryption, and it does validate the server certificate, but that validation is only a small part of the inspection process. Since it also inspects and potentially blocks content, it cannot be described as only validating the server certificate.
- ✗
Flow-based inspection
Why it's wrong here
Flow-based inspection is wrong because it is not an SSL/TLS inspection mode at all; it is a security processing mode that determines how FortiGate applies inspection engines (either flow-based or proxy-based). In flow-based mode, the device uses a single-pass, low-latency asynchronous (NPU offloading capable) scanning engine, and it can support certificate inspection or deep inspection depending on the configured SSL/SSH inspection profile. Therefore, it does not itself define or limit what happens to the server certificate, making it an incorrect answer to the question.
- ✓
Certificate inspection
Why this is correct
Certificate inspection is correct because this SSL/TLS inspection mode only validates the server certificate and does not perform any decryption of the encrypted session. FortiGate forwards the client hello, receives the server certificate, and verifies its validity (e.g., signing chain, issuer, trust, and possible revocation) while leaving the payload encrypted and untouched. This mode is lightweight, preserves performance, and is typically used when you only need to enforce certificate-based policies or ensure clients do not connect to untrusted servers. It does not inspect application content, making it the only mode that strictly only validates the server certificate.
- ✗
Proxy-based inspection
Why it's wrong here
Proxy-based inspection is wrong because it refers to a security processing mode similar to flow-based, not a distinct SSL/TLS inspection profile. In proxy-based mode, FortiGate terminates and re-establishes the connection, which enables the full deep inspection features such as re-encryption and application-layer content scanning; it can certainly validate the server certificate, but it also performs decryption and content inspection when configured with deep inspection. As a mode of operation, it does not by itself answer the question of which inspection mode only validates the certificate—that behavior is tied to the certificate inspection profile, not the proxy-based processing engine.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.