nerdexam
Fortinet

NSE4 · Question #17

Which statements are true regarding traffic shaping that is applied in an application sensor, and associated with a firewall policy? (Choose two.)

The correct answer is B. Only traffic matching the application control signature is shaped. C. Can limit the bandwidth usage of heavy traffic applications. When traffic shaping is applied within an application control sensor and linked to a firewall policy, it specifically shapes only the traffic identified by the application control signature, and it is highly effective at limiting the bandwidth usage of identified heavy-traffic…

Submitted by dimitri_ru· Apr 18, 2026Security Profiles and Content Inspection

Question

Which statements are true regarding traffic shaping that is applied in an application sensor, and associated with a firewall policy? (Choose two.)

Options

  • AShared traffic shaping cannot be used.
  • BOnly traffic matching the application control signature is shaped.
  • CCan limit the bandwidth usage of heavy traffic applications.
  • DPer-IP traffic shaping cannot be used.

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    89% (16)
  • D
    6% (1)

Why each option

When traffic shaping is applied within an application control sensor and linked to a firewall policy, it specifically shapes only the traffic identified by the application control signature, and it is highly effective at limiting the bandwidth usage of identified heavy-traffic applications.

AShared traffic shaping cannot be used.

Both shared and per-IP traffic shapers can be used with application control; there is no restriction preventing shared shapers.

BOnly traffic matching the application control signature is shaped.Correct

Traffic shapers applied directly within an application control profile are granular; they only affect the specific traffic streams that are identified and matched by the application control signature configured in that profile.

CCan limit the bandwidth usage of heavy traffic applications.Correct

A primary use case for applying traffic shaping through application control is to manage and limit the bandwidth consumed by specific applications, especially those known for high bandwidth usage like streaming, peer-to-peer, or gaming.

DPer-IP traffic shaping cannot be used.

Per-IP traffic shapers can be applied when defining traffic shaping in an application control profile, allowing for granular control of bandwidth per source or destination IP for specific applications.

Concept tested: FortiGate application control traffic shaping characteristics

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/336495/configuring-application-control

Topics

#Traffic Shaping#Application Control#Security Profiles#Bandwidth Management

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice