nerdexam
Fortinet

NSE4 · Question #15

Which statements are correct regarding application control? (Choose two.)

The correct answer is A. It is based on the IPS engine. C. It can be applied to SSL encrypted traffic. FortiGate's application control utilizes the IPS engine for traffic inspection and can effectively classify and control applications within SSL-encrypted traffic when SSL inspection is enabled.

Submitted by brentm· Apr 18, 2026Security Profiles and Content Inspection

Question

Which statements are correct regarding application control? (Choose two.)

Options

  • AIt is based on the IPS engine.
  • BIt is based on the AV engine.
  • CIt can be applied to SSL encrypted traffic.
  • DApplication control cannot be applied to SSL encrypted traffic.

How the community answered

(21 responses)
  • A
    95% (20)
  • D
    5% (1)

Why each option

FortiGate's application control utilizes the IPS engine for traffic inspection and can effectively classify and control applications within SSL-encrypted traffic when SSL inspection is enabled.

AIt is based on the IPS engine.Correct

Application control on FortiGate leverages the Intrusion Prevention System (IPS) engine, which performs deep packet inspection to identify and categorize applications based on their unique signatures and behavioral patterns.

BIt is based on the AV engine.

Application control is not based on the antivirus (AV) engine; the AV engine is primarily for detecting malware, while application control focuses on identifying and managing applications.

CIt can be applied to SSL encrypted traffic.Correct

Application control can be applied to SSL encrypted traffic, provided that SSL inspection (deep inspection) is enabled on the FortiGate unit. This allows the FortiGate to decrypt, inspect, and then re-encrypt the traffic, enabling application identification and control within encrypted sessions.

DApplication control cannot be applied to SSL encrypted traffic.

This statement is incorrect because application control can indeed be applied to SSL encrypted traffic if SSL deep inspection is configured and enabled on the FortiGate.

Concept tested: FortiGate application control engine and SSL inspection

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/466668/about-application-control

Topics

#Application Control#IPS Engine#SSL Inspection#Security Profiles

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice