nerdexam
Fortinet

NSE4 · Question #253

Which of the following items are considered to be advantages of using the application control features on the FortiGate unit? Application control allows an administor to:

The correct answer is A. set a unique session-ttl for select applications. FortiGate's application control allows administrators to set unique session Time-To-Live (TTL) values for specific applications, enabling granular control over session durations.

Submitted by the_admin· Apr 18, 2026Security Profiles and Content Inspection

Question

Which of the following items are considered to be advantages of using the application control features on the FortiGate unit? Application control allows an administor to:

Options

  • Aset a unique session-ttl for select applications.
  • Bcustomize application types in a similar way to adding custom IPS signatures.
  • Ccheck which applications are installed on workstations attempting to access the network.
  • Denable AV scanning per application rather than per policy.

How the community answered

(45 responses)
  • A
    87% (39)
  • B
    2% (1)
  • C
    4% (2)
  • D
    7% (3)

Why each option

FortiGate's application control allows administrators to set unique session Time-To-Live (TTL) values for specific applications, enabling granular control over session durations.

Aset a unique session-ttl for select applications.Correct

FortiGate's application control feature allows administrators to define different session Time-To-Live (TTL) values for specific applications, often through linked protocol options profiles. This granular control helps optimize network resources and security by closing idle application sessions or keeping critical application sessions open longer.

Bcustomize application types in a similar way to adding custom IPS signatures.

While FortiGate supports custom application signatures, this is typically part of advanced signature development rather than a standard customization within the application control interface, which primarily identifies existing application types.

Ccheck which applications are installed on workstations attempting to access the network.

Application control identifies applications in transit on the network; it does not check which applications are installed on workstations, which is a function of endpoint security or inventory tools.

Denable AV scanning per application rather than per policy.

AV scanning is typically enabled per firewall policy, affecting all traffic matching that policy, not on a per-application basis within the application control feature itself.

Concept tested: FortiGate application control session TTL configuration

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/330528/session-ttl-settings-for-protocol-options

Topics

#Application Control#FortiGate#Session Management#Firewall Policies

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice