NSE7 Advanced Threat Protection Practice Question
A FortiGate is configured with an SSL inspection profile that uses a deep-inspection mode. Users complain that a banking website fails to load, but HTTP sites work. The administrator confirms the site uses TLS 1.3 with Encrypted Client Hello (ECH) and certificate pinning. Which action should the administrator take to restore access while maintaining visibility for other traffic?
⚠ Common exam trap
The trap here is assuming that changing the inspection mode globally or disabling TLS 1.3 will fix the site, when the correct approach is a targeted exemption for that destination.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the banking website to the SSL inspection exemption list.
The banking site fails because deep SSL inspection intercepts TLS 1.3 with Encrypted Client Hello and certificate pinning, which breaks the connection. Exempting the specific destination from SSL inspection restores access without sacrificing visibility for other traffic. Global changes like switching to certificate-inspection or disabling TLS 1.3 reduce security for all connections and do not target the root cause.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the SSL inspection profile to certificate-inspection mode.
Why it's wrong here
Switching to certificate-inspection mode would stop decrypting all traffic for all destinations, not just the banking site. While it might allow the banking site to load, it removes deep visibility for every other connection, which violates the requirement to maintain visibility. The issue is specific to one site, so a global change is inappropriate.
- ✗
Enable the 'allow invalid server certificates' option in the SSL inspection profile.
Why it's wrong here
Allowing invalid server certificates would not help with a valid pinned certificate; the problem is that deep inspection replaces the certificate, which pinning rejects. This option weakens security by permitting expired or self-signed certificates and does not address the pinning or ECH conflict. It may also cause other security warnings.
- ✓
Add the banking website to the SSL inspection exemption list.
Why this is correct
Exempting the banking site from SSL inspection bypasses deep inspection for that destination only. Because the site uses TLS 1.3 with Encrypted Client Hello and certificate pinning, deep inspection breaks the connection; an exemption restores access while other traffic remains inspected. This is the standard FortiGate method to handle pinned or ECH-enabled sites without disabling inspection globally.
- ✗
Disable TLS 1.3 support on the FortiGate SSL inspection profile.
Why it's wrong here
Disabling TLS 1.3 support does not resolve certificate pinning or ECH issues; the client and server may still negotiate TLS 1.3 or the pinning will still cause failures. Moreover, this degrades security for all inspected traffic and may break other modern sites. It is not a targeted fix for the banking site.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.