nerdexam
Fortinet

NSE4 · Question #289

Which of the following statements correctly describes the deepscan option for HTTPS?

The correct answer is A. When deepscan is disabled, only the web server certificate is inspected; no decryption of content. When the 'deepscan' option is disabled for HTTPS, the FortiGate only inspects the web server's certificate for validity and trust, without decrypting or inspecting the actual content of the encrypted traffic.

Submitted by jakub_pl· Apr 18, 2026Security Profiles and Content Inspection

Question

Which of the following statements correctly describes the deepscan option for HTTPS?

Options

  • AWhen deepscan is disabled, only the web server certificate is inspected; no decryption of content
  • BEnabling deepscan will perform further checks on the server certificate.
  • CDeepscan is only applicable to mail protocols, where all IP addresses in the header are checked.
  • DWith deepscan enabled, archived files will be decompressed before scanning for a more

How the community answered

(26 responses)
  • A
    92% (24)
  • C
    4% (1)
  • D
    4% (1)

Why each option

When the 'deepscan' option is disabled for HTTPS, the FortiGate only inspects the web server's certificate for validity and trust, without decrypting or inspecting the actual content of the encrypted traffic.

AWhen deepscan is disabled, only the web server certificate is inspected; no decryption of contentCorrect

When deepscan (referring to full SSL/TLS inspection) is disabled for HTTPS, the FortiGate will still inspect the web server certificate to ensure it is valid and trusted, but it will not perform decryption of the encrypted content, meaning no further inspection of the payload occurs.

BEnabling deepscan will perform further checks on the server certificate.

Enabling deepscan does more than just further check the server certificate; its primary function is to decrypt and inspect the *content* of the encrypted traffic for security threats or policy violations.

CDeepscan is only applicable to mail protocols, where all IP addresses in the header are checked.

Deepscan functionality is primarily associated with HTTP/HTTPS and other encrypted protocols for content inspection, not exclusively mail protocols, and its purpose is not limited to checking IP addresses in headers.

DWith deepscan enabled, archived files will be decompressed before scanning for a more

While deepscan generally implies thorough scanning, the decompression and scanning of archived files is a feature of antivirus/sandboxing engines, not the core definition of 'deepscan' specifically for HTTPS protocol handling in the context of SSL inspection.

Concept tested: FortiGate SSL/TLS Inspection Modes

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/526779/ssl-ssh-inspection

Topics

#HTTPS Inspection#SSL Inspection#Deep Inspection#Security Profiles

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice