nerdexam
Fortinet

NSE4 · Question #286

The transfer of encrypted files or the use of encrypted protocols between users and servers on the internet can frustrate the efforts of administrators attempting to monitor traffic passing through…

The correct answer is A. Encrypted protocols can be scanned through the use of the SSL proxy. B. DLP rules can be used to block the transmission of encrypted files. D. Application control can be used to monitor the use of encrypted protocols; alerts can be sent to. Administrators can control encrypted data transfer by enabling SSL/TLS inspection (SSL proxy) to decrypt and scan protocols, using DLP rules to block encrypted files, and employing Application Control to monitor and alert on encrypted protocol usage.

Submitted by rachelw· Apr 18, 2026Security Profiles and Content Inspection

Question

The transfer of encrypted files or the use of encrypted protocols between users and servers on the internet can frustrate the efforts of administrators attempting to monitor traffic passing through the FortiGate unit and ensuring user compliance to corporate rules. Which of the following items will allow the administrator to control the transfer of encrypted data through the FortiGate unit? (Select all that apply.)

Options

  • AEncrypted protocols can be scanned through the use of the SSL proxy.
  • BDLP rules can be used to block the transmission of encrypted files.
  • CFirewall authentication can be enabled in the firewall policy, preventing the use of encrypted
  • DApplication control can be used to monitor the use of encrypted protocols; alerts can be sent to

How the community answered

(23 responses)
  • A
    83% (19)
  • C
    17% (4)

Why each option

Administrators can control encrypted data transfer by enabling SSL/TLS inspection (SSL proxy) to decrypt and scan protocols, using DLP rules to block encrypted files, and employing Application Control to monitor and alert on encrypted protocol usage.

AEncrypted protocols can be scanned through the use of the SSL proxy.Correct

The FortiGate's SSL/TLS inspection (often referred to as an SSL proxy) functionality allows it to decrypt encrypted traffic, inspect its content for threats or policy violations, and then re-encrypt it before forwarding, enabling control over encrypted protocols.

BDLP rules can be used to block the transmission of encrypted files.Correct

Data Leak Prevention (DLP) can be configured to detect and block the transmission of encrypted files based on their file type signatures (e.g., specific headers or metadata indicating encryption), even if the content cannot be read without decryption.

CFirewall authentication can be enabled in the firewall policy, preventing the use of encrypted

Firewall authentication ensures that only authorized users can pass traffic through the firewall, but it does not inherently prevent or control the *type* of encrypted protocols those authenticated users choose to employ once access is granted.

DApplication control can be used to monitor the use of encrypted protocols; alerts can be sent toCorrect

Application Control can identify and monitor the use of specific encrypted protocols (e.g., SSH, HTTPS, various VPN applications) by analyzing traffic patterns and port numbers, allowing administrators to enforce policies, log usage, or generate alerts without full content decryption.

Concept tested: FortiGate Encrypted Traffic Control

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/526779/ssl-ssh-inspection

Topics

#SSL Inspection#DLP#Application Control#Encrypted Traffic

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice