nerdexam
Fortinet

NSE4 · Question #220

Examine the exhibit shown below then answer the question that follows it. Within the UTM Proxy Options, the CA certificate Fortinet_CA_SSLProxy defines which of the following:

The correct answer is A. FortiGate unit's encryption certificate used by the SSL proxy. The Fortinet_CA_SSLProxy certificate within FortiGate's UTM Proxy Options defines the FortiGate unit's certificate that is used by the SSL proxy to perform deep inspection and decryption of encrypted traffic.

Submitted by hassan_iq· Apr 18, 2026Security Profiles and Content Inspection

Question

Examine the exhibit shown below then answer the question that follows it. Within the UTM Proxy Options, the CA certificate Fortinet_CA_SSLProxy defines which of the following:

Exhibit

NSE4 question #220 exhibit

Options

  • AFortiGate unit's encryption certificate used by the SSL proxy.
  • BFortiGate unit's signing certificate used by the SSL proxy.
  • CFortiGuard's signing certificate used by the SSL proxy.
  • DFortiGuard's encryption certificate used by the SSL proxy.

How the community answered

(65 responses)
  • A
    89% (58)
  • B
    3% (2)
  • C
    2% (1)
  • D
    6% (4)

Why each option

The Fortinet_CA_SSLProxy certificate within FortiGate's UTM Proxy Options defines the FortiGate unit's certificate that is used by the SSL proxy to perform deep inspection and decryption of encrypted traffic.

AFortiGate unit's encryption certificate used by the SSL proxy.Correct

The `Fortinet_CA_SSLProxy` certificate is a built-in Certificate Authority (CA) certificate on the FortiGate unit that, when SSL deep inspection is enabled, is used to dynamically generate and sign certificates for intercepted SSL connections, enabling the FortiGate to decrypt, inspect, and then re-encrypt traffic.

BFortiGate unit's signing certificate used by the SSL proxy.

While it is used for signing, it primarily functions as the encryption certificate of the FortiGate itself for the purpose of proxying, not just a generic 'signing certificate'.

CFortiGuard's signing certificate used by the SSL proxy.

`Fortinet_CA_SSLProxy` is generated and managed by the FortiGate itself, not FortiGuard, which provides threat intelligence, not the local SSL inspection CA.

DFortiGuard's encryption certificate used by the SSL proxy.

This certificate is associated with the FortiGate unit's local SSL proxy functionality, not with FortiGuard services.

Concept tested: FortiGate SSL Proxy CA certificate

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/523930/ssl-inspection-and-certificates

Topics

#SSL Inspection#Certificates#FortiGate#Proxy Options

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice