nerdexam
Fortinet

NSE4 · Question #248

SSL Proxy is used to decrypt the SSL-encrypted traffic. After decryption, where is the traffic buffered in preparation for content inspection?

The correct answer is A. The file is buffered by the application proxy. After the SSL proxy decrypts encrypted traffic, the unencrypted content is passed to the application-layer proxies, which then buffer the data for subsequent content inspection by various security modules.

Submitted by parkjh· Apr 18, 2026Security Profiles and Content Inspection

Question

SSL Proxy is used to decrypt the SSL-encrypted traffic. After decryption, where is the traffic buffered in preparation for content inspection?

Options

  • AThe file is buffered by the application proxy.
  • BThe file is buffered by the SSL proxy.
  • CIn the upload direction, the file is buffered by the SSL proxy.
  • DNo file buffering is needed since a stream-based scanning approach is used for SSL content

How the community answered

(30 responses)
  • A
    90% (27)
  • B
    7% (2)
  • D
    3% (1)

Why each option

After the SSL proxy decrypts encrypted traffic, the unencrypted content is passed to the application-layer proxies, which then buffer the data for subsequent content inspection by various security modules.

AThe file is buffered by the application proxy.Correct

When the SSL proxy decrypts traffic, the decrypted data stream is forwarded to the relevant application-layer proxy (e.g., HTTP proxy for web traffic). This application proxy then buffers the content for further security inspections such as antivirus, IPS, or data loss prevention before re-encrypting and forwarding it.

BThe file is buffered by the SSL proxy.

The SSL proxy's primary role is decryption and re-encryption; the actual buffering for deep content inspection typically occurs at the application proxy level after the data is decrypted.

CIn the upload direction, the file is buffered by the SSL proxy.

Even in the upload direction, the SSL proxy handles the secure tunnel, but the buffering required for thorough content inspection is usually performed by the application-layer proxy.

DNo file buffering is needed since a stream-based scanning approach is used for SSL content

File buffering is often necessary for comprehensive content inspection by security features like antivirus scanning, which require examining the complete file rather than just a continuous stream to detect threats effectively.

Concept tested: FortiGate SSL proxy and content inspection buffering

Source: https://docs.fortinet.com/document/fortigate/7.0.0/security-fabric-administration-guide/209971/ssl-inspection

Topics

#SSL Proxy#Content Inspection#Traffic Buffering#Application Proxy

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice