Courseiva
Security Profiles →mediumMultiple Select

NSE4 Security Profiles Practice Question

Which TWO actions can cause SSL inspection to fail with certificate errors on client browsers? (Choose two.)

⚠ Common exam trap

Watch out — candidates often assume a public CA-signed server certificate is always trusted during inspection, forgetting that the FortiGate re-signs the certificate with its own CA, so the browser only sees the FortiGate's CA certificate and the generated server certificate, not the original public CA certificate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The FortiGate's CA certificate has expired.

The FortiGate acts as a certificate authority (CA) for SSL inspection. If the FortiGate's CA certificate has expired, any server certificate it generates and signs for intercepted HTTPS sessions will be considered invalid by client browsers. Browsers will display a certificate error because the signing CA (the FortiGate) is no longer trusted due to expiration, even if the client has the CA certificate installed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The FortiGate's CA certificate has expired.

    Why this is correct

    When the FortiGate's internal CA certificate is past its validity period, the FortiGate can no longer sign or re-sign the server certificates it presents to clients. Even if the generated leaf certificate has a future validity window, the browser will validate the entire chain and immediately flag the root/intermediate CA as expired, breaking trust and causing an 'untrusted authority' error during SSL inspection.

  • ✗

    The firewall policy allows the traffic.

    Why it's wrong here

    A firewall policy that permits traffic is the fundamental prerequisite for enabling SSL inspection—not a failure condition. Without a permit action, the session would be dropped or rejected outright, so simply allowing traffic cannot introduce a certificate error. Inspection errors arise from cryptographic and trust issues, not from the policy's action field.

  • ✗

    The web server's certificate is signed by a public CA.

    Why it's wrong here

    The remote web server's certificate being issued by a well-known public CA is the expected, standard scenario for HTTPS traffic. During full SSL inspection, the FortiGate terminates the TLS session from the server, validates the public CA signature itself, and then presents a new certificate signed by its own local CA to the client. Thus, a public CA on the server side poses no inherent problem; failures only occur if the FortiGate's own CA is not trusted by the client.

  • ✗

    The client browser has the FortiGate CA certificate installed.

    Why it's wrong here

    Having the FortiGate's CA certificate installed in the client browser is precisely the remediation step that prevents SSL inspection failures. It establishes the FortiGate as a trusted root, so the dynamically generated server certificates chain up to a trusted anchor. This action cannot cause certificate errors; on the contrary, its absence is the leading source of 'untrusted connection' warnings.

  • ✓

    The FortiGate's generated server certificate does not match the requested domain name.

    Why this is correct

    If the FortiGate generates a server certificate whose Subject Common Name (CN) or Subject Alternative Name (SAN) does not match the DNS name in the client's request, modern browsers will abort the handshake with a domain mismatch error. This typically occurs when inspection rules use a wildcard CA or when a single policy must handle multiple virtual hosts without proper certificate substitution based on SNI.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.