SSL inspection in proxy mode goes through the WAD daemon; checking WAD confirms inspection.
Why this answer
'diagnose wad filter' is used to verify that traffic is being processed by the web proxy (WAD) for SSL inspection. When SSL inspection is enabled, traffic on port 443 is intercepted by the FortiGate's proxy, and this command filters and displays relevant proxy sessions, confirming that decryption is occurring.
Exam trap
The trap here is that candidates often confuse 'diagnose debug flow' with confirming SSL inspection, but it only verifies policy matching, not the actual decryption process handled by the proxy.