NSE7 Troubleshooting and Diagnostics Practice Question
A FortiGate admin notices that HTTPS traffic to a web server is not being scanned by the antivirus profile applied to the firewall policy. The admin confirms the policy is correct and antivirus is enabled. What is the MOST likely reason the traffic is not being scanned?
⚠ Common exam trap
Candidates often assume antivirus scanning works on all traffic by default, but they overlook the critical prerequisite of SSL/TLS deep inspection to decrypt HTTPS before scanning can occur.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSL/TLS deep inspection is not enabled on the firewall policy
When HTTPS traffic is not scanned by an antivirus profile despite the policy being correct and antivirus enabled, the most likely cause is that SSL/TLS deep inspection is not enabled on the firewall policy. Without deep inspection, FortiGate cannot decrypt the encrypted HTTPS payload, so the antivirus engine sees only encrypted data and cannot scan for malware. Enabling deep inspection with a valid CA certificate allows FortiGate to perform man-in-the-middle decryption and then apply antivirus scanning to the decrypted content.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SSL/TLS deep inspection is not enabled on the firewall policy
Why this is correct
Antivirus profiles inspect decrypted payloads, so HTTPS traffic remains encrypted and passes unscanned unless SSL/TLS deep inspection is enabled on the policy. Enabling deep inspection lets FortiGate decrypt, scan, then re-encrypt the session, satisfying the requirement that HTTPS be examined.
- ✗
The web server's certificate is self-signed and FortiGate is rejecting the connection
Why it's wrong here
FortiGate does not reject self-signed server certificates during antivirus scanning; certificate validation is a separate inspection concern and does not block content scanning. The tempting link is that certificate errors do disrupt SSL inspection, but that occurs with full inspection and untrusted CA chains, not with the antivirus profile itself.
- ✗
The FortiGuard antivirus subscription has expired
Why it's wrong here
An expired FortiGuard subscription stops signature updates, yet existing antivirus signatures still scan traffic, so scanning would not cease entirely. Subscription licensing matters for keeping detection current, but a complete absence of scanning indicates the traffic bypasses inspection, such as via certificate or exemption settings.
- ✗
The antivirus profile is configured for flow-based inspection instead of proxy-based
Why it's wrong here
Flow-based inspection performs antivirus scanning only on files in protocols it supports and cannot buffer or decompress all HTTPS content the way proxy-based mode does, so scanning may be skipped. Flow-based is tempting because it offers lower latency and higher throughput, and would be correct where performance matters more than deep content inspection.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.