Courseiva
Advanced Threat Protection →mediumMultiple Choice

NSE7 Advanced Threat Protection Practice Question

An administrator is configuring FortiGate to inspect SSL traffic for malware. They enable deep inspection in the SSL inspection profile and apply it to a firewall policy. Users report that some HTTPS websites are showing certificate errors. What is the most likely cause?

⚠ Common exam trap

The trap here is assuming that any certificate error under deep inspection is due to an untrusted CA, when certificate pinning is a common and specific cause that cannot be resolved by simply trusting the CA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The websites are using certificate pinning, which prevents deep inspection.

Certificate pinning in applications or browsers causes certificate errors when deep inspection is used because the FortiGate presents a re-signed certificate that does not match the pinned certificate. Administrators should exempt such sites from deep inspection or use a different inspection method.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The SSL inspection profile is set to protect only the server, not the client.

    Why it's wrong here

    SSL inspection profiles can be configured for client or server protection. For outbound traffic, client protection is used. If set incorrectly, inspection might not occur, but it would not cause certificate errors. Certificate errors are due to trust issues, not the protection mode.

  • ✗

    The FortiGate is using a self-signed certificate for deep inspection.

    Why it's wrong here

    Using a self-signed certificate for deep inspection will cause certificate warnings unless the certificate is trusted by the clients. However, the scenario does not specify the certificate type. The more common cause of certificate errors is the lack of the CA certificate in the client's trust store, which applies regardless of whether the certificate is self-signed or from a public CA.

  • ✗

    The FortiGate is not configured to use SNI for SSL inspection.

    Why it's wrong here

    SNI is used to identify the hostname during the SSL handshake. While SNI is important for proper inspection, lack of SNI configuration does not typically cause certificate errors. It might cause inspection failures or incorrect categorization, but not certificate trust issues.

  • ✓

    The websites are using certificate pinning, which prevents deep inspection.

    Why this is correct

    Certificate pinning is a security mechanism where the application or browser expects a specific certificate or public key. When FortiGate performs deep inspection, it re-signs the certificate, breaking the pin and causing an error. This is a common reason why some HTTPS sites fail under deep inspection.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.