NSE7 Advanced Threat Protection Practice Question
A FortiGate administrator is configuring SSL inspection on a policy that handles outbound HTTPS traffic. Users report that after enabling deep inspection, some business-critical applications that use certificate pinning fail. The administrator needs to inspect as much traffic as possible while keeping those pinned applications working. What should the administrator do?
⚠ Common exam trap
The trap here is assuming that disabling SSL inspection or importing certificates is an acceptable substitute for a targeted SSL exemption when certificate-pinned applications must keep working.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an exemption in the SSL inspection profile for the pinned applications and apply deep inspection to the remaining traffic.
Deep inspection is required to examine encrypted traffic for threats, but certificate-pinned applications will reject the FortiGate's re-signed certificate. The supported approach is to add those applications or destinations to an SSL exemption so they are not decrypted, while deep inspection continues for everything else. This balances security visibility with application availability and is the recommended operational practice for mixed traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the policy to use full SSL inspection and import the pinned applications' certificates as trusted CAs on the FortiGate.
Why it's wrong here
Importing pinned application certificates as trusted CAs on the FortiGate does not resolve the client-side pinning issue, because the endpoint still validates the original certificate chain. The FortiGate would still re-sign the session with its own certificate, causing the pinned application to reject the connection. This does not preserve functionality for those applications.
- ✗
Disable SSL inspection entirely on the policy and rely on the application control profile to identify the pinned applications.
Why it's wrong here
Application control can classify applications using protocol behavior and metadata, but it cannot inspect the encrypted payload of HTTPS sessions. Disabling SSL inspection removes the ability to see threats inside TLS, so this approach does not meet the requirement to inspect as much traffic as possible and weakens overall protection for the policy.
- ✓
Create an exemption in the SSL inspection profile for the pinned applications and apply deep inspection to the remaining traffic.
Why this is correct
An SSL exemption lets the FortiGate bypass decryption for specified destinations or applications that use certificate pinning, while deep inspection continues for all other HTTPS traffic. This satisfies the goal of inspecting as much traffic as possible without breaking the pinned applications, and it is the supported way to handle pinned or sensitive traffic in a deep-inspection policy.
- ✗
Set the SSL inspection profile to certificate-inspection for the policy and leave the rest of the traffic uninspected.
Why it's wrong here
Certificate inspection only examines the server certificate and cannot see inside the encrypted session, so malware hidden in HTTPS payloads would not be detected. It would allow the pinned applications to work, but it fails the requirement to inspect as much traffic as possible and leaves the policy unable to perform full content inspection for the majority of sessions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.