Courseiva
Security Profiles →mediumMultiple Select

NSE4 Security Profiles Practice Question

Which TWO of the following are required for full SSL inspection to work correctly?

⚠ Common exam trap

Many exam-takers think the FortiGate needs the server's private key (Option A) to decrypt traffic, but in reality, full SSL inspection uses a man-in-the-middle approach where the FortiGate generates its own session certificates, requiring only its own CA certificate and client trust.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The FortiGate's CA certificate installed in the Trusted Root Certification Authorities store on client machines.

For full SSL inspection, the FortiGate must generate a session certificate on-the-fly for each HTTPS connection after decrypting it. This requires a CA certificate on the FortiGate to sign those session certificates. Additionally, client machines must trust this CA certificate, so it must be installed in their Trusted Root Certification Authorities store; otherwise, browsers will show certificate warnings and block the connection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The private key of each server certificate that will be inspected.

    Why it's wrong here

    During full SSL inspection, the FortiGate operates as a middlebox, establishing a separate TLS session with the client and another with the origin server. It does not possess or need the server's private key; instead, it uses the server's public certificate to encrypt the upstream connection. The per-session certificates presented to clients are dynamically generated and signed by the FortiGate's own CA, so the server's private key is never a component of the inspection process.

  • ✓

    The FortiGate's CA certificate installed in the Trusted Root Certification Authorities store on client machines.

    Why this is correct

    This is a mandatory step because the FortiGate signs every session certificate it sends to clients using its own CA. Without adding that CA certificate to the Trusted Root Certification Authorities store, clients will reject the presented certificate as untrusted and display SSL errors or refuse the connection. This trust installation must be performed on every client that will have its traffic inspected, typically via Group Policy or MDM.

  • ✗

    An intermediate CA certificate imported from the enterprise PKI.

    Why it's wrong here

    Integrating an enterprise PKI's intermediate CA is not a requirement for full SSL inspection; it is an optional configuration that lets the FortiGate chain its generated certificates to a corporate root. The FortiGate can rely on its own standalone self-signed CA, which is automatically created during initial setup. Only when strict corporate certificate policies demand a specific subordinate CA would this import be needed, but the inspection function itself works without it.

  • ✓

    A certificate on the FortiGate to generate session certificates.

    Why this is correct

    The FortiGate must have a CA certificate with a private key on the device, used to sign the certificates it creates for each intercepted host. This is the engine of full SSL inspection; without it, the FortiGate cannot fabricate the server impersonation certificates that clients see. This CA certificate is typically self-signed and is the same certificate that must be installed on client machines for trust.

  • ✗

    A certificate signed by a public CA installed on the FortiGate.

    Why it's wrong here

    A public-CA-signed certificate on the FortiGate is not related to SSL inspection; that type of certificate is used for identifying the FortiGate itself, such as for the web admin interface or SSL VPN. The FortiGate's inspection CA is internally generated and self-signed, not issued by a public CA. If a public CA certificate were used, clients still would not trust its dynamic certificates unless the corresponding CA is in their root store, so this option is both wrong and unnecessary.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.