NSE7 Advanced Threat Protection Practice Question
An administrator is configuring FortiGate to inspect SSL traffic for malware. They enable deep inspection in the SSL inspection profile and apply it to a firewall policy. Users report that some HTTPS websites are showing certificate errors. What is the most likely cause?
⚠ Common exam trap
The trap here is assuming that any certificate error under deep inspection is due to an untrusted CA, when certificate pinning is a common and specific cause that cannot be resolved by simply trusting the CA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The websites are using certificate pinning, which prevents deep inspection.
Certificate pinning in applications or browsers causes certificate errors when deep inspection is used because the FortiGate presents a re-signed certificate that does not match the pinned certificate. Administrators should exempt such sites from deep inspection or use a different inspection method.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The SSL inspection profile is set to protect only the server, not the client.
Why it's wrong here
SSL inspection profiles can be configured for client or server protection. For outbound traffic, client protection is used. If set incorrectly, inspection might not occur, but it would not cause certificate errors. Certificate errors are due to trust issues, not the protection mode.
- ✗
The FortiGate is using a self-signed certificate for deep inspection.
Why it's wrong here
Using a self-signed certificate for deep inspection will cause certificate warnings unless the certificate is trusted by the clients. However, the scenario does not specify the certificate type. The more common cause of certificate errors is the lack of the CA certificate in the client's trust store, which applies regardless of whether the certificate is self-signed or from a public CA.
- ✗
The FortiGate is not configured to use SNI for SSL inspection.
Why it's wrong here
SNI is used to identify the hostname during the SSL handshake. While SNI is important for proper inspection, lack of SNI configuration does not typically cause certificate errors. It might cause inspection failures or incorrect categorization, but not certificate trust issues.
- ✓
The websites are using certificate pinning, which prevents deep inspection.
Why this is correct
Certificate pinning is a security mechanism where the application or browser expects a specific certificate or public key. When FortiGate performs deep inspection, it re-signs the certificate, breaking the pin and causing an error. This is a common reason why some HTTPS sites fail under deep inspection.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.