Courseiva
Security Profiles →easyMultiple Select

NSE4 Security Profiles Practice Question

Which TWO types of inspection can be used for HTTPS traffic in a FortiGate security policy?

⚠ Common exam trap

Candidates often confuse processing modes (flow-based and proxy-based) with inspection types (deep and certificate), leading them to select flow-based or proxy-based as inspection methods instead of recognizing them as underlying operational modes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deep inspection

FortiGate security policies can inspect HTTPS traffic using either deep inspection or certificate inspection. Deep inspection decrypts the SSL/TLS session, inspects the full payload for threats like malware or data leakage, and re-encrypts the traffic, while certificate inspection only validates the server certificate without decrypting the content, checking for certificate validity and revocation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deep inspection

    Why this is correct

    Deep inspection decrypts SSL/TLS traffic, inspects the full payload and headers for threats, then re-encrypts it before forwarding. This allows FortiGate to detect malicious content hidden inside encrypted sessions, but requires clients to trust a FortiGate CA certificate. It is one of the two valid HTTPS inspection types in Fortinet's NSE4 curriculum.

  • ✓

    Certificate inspection

    Why this is correct

    Certificate inspection only evaluates the SSL/TLS certificate presented by the server, checking its validity, trust chain, and Common Name, without decrypting the encrypted payload. It can block sessions based on certificate attributes or mismatches, but cannot scan content. This lightweight method is the other valid HTTPS inspection type alongside deep inspection.

  • ✗

    Full inspection

    Why it's wrong here

    Full inspection is not a recognized HTTPS inspection type in Fortinet's terminology. Fortinet distinguishes only between certificate inspection and deep inspection for encrypted traffic; 'full inspection' is an ambiguous term that might be mistakenly used to describe deep inspection but does not correspond to any specific FortiGate feature. Therefore, it is an incorrect option.

  • ✗

    Flow-based inspection

    Why it's wrong here

    Flow-based inspection is a FortiGate processing mode that leverages a single-pass, low-latency security engine, commonly used for high-throughput scenarios. It is not a type of HTTPS inspection; rather, it determines how policies enforce inspection, which for HTTPS can still only be certificate or deep inspection. Thus, flow-based is a mode, not an inspection type.

  • ✗

    Proxy-based inspection

    Why it's wrong here

    Proxy-based inspection is a FortiGate processing mode that terminates the client connection and creates a separate server connection, allowing deep protocol analysis and re-encryption. It is a mechanism for inspecting traffic, including HTTPS, but it is not a distinct inspection type; the actual HTTPS inspection type remains either certificate or deep inspection. Therefore, proxy-based inspection is an incorrect option.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.