nerdexam
Fortinet

NSE4 · Question #331

Which statements about application control are true? (Choose two.)

The correct answer is A. Enabling application control profile in a security profile enables application control for all the traffic D. It can identify traffic from known applications, even when they are using non-standard TCP/UDP. FortiGate's application control, when enabled in a security profile and applied to a policy, inspects all relevant traffic and can identify known applications even if they use non-standard ports.

Submitted by omar99· Apr 18, 2026Security Profiles and Content Inspection

Question

Which statements about application control are true? (Choose two.)

Options

  • AEnabling application control profile in a security profile enables application control for all the traffic
  • BIt cannot take an action on unknown applications.
  • CIt can inspect encrypted traffic.
  • DIt can identify traffic from known applications, even when they are using non-standard TCP/UDP

How the community answered

(51 responses)
  • A
    88% (45)
  • B
    8% (4)
  • C
    4% (2)

Why each option

FortiGate's application control, when enabled in a security profile and applied to a policy, inspects all relevant traffic and can identify known applications even if they use non-standard ports.

AEnabling application control profile in a security profile enables application control for all the trafficCorrect

When an application control profile is enabled within a security policy, it will actively attempt to identify and apply configured actions to all network traffic that matches that policy, rather than just specific types.

BIt cannot take an action on unknown applications.

Application control can indeed take action on unknown applications, such as blocking them or classifying them as 'Unknown' for further investigation.

CIt can inspect encrypted traffic.

Application control cannot directly inspect the content of encrypted traffic without SSL/TLS inspection (deep inspection) being also enabled and performed by the FortiGate to decrypt the traffic first.

DIt can identify traffic from known applications, even when they are using non-standard TCP/UDPCorrect

FortiGate's application control uses advanced techniques like deep packet inspection (DPI), heuristic analysis, and protocol decoders to identify applications based on their unique signatures and behavior, allowing detection even when applications attempt to evade by using non-standard TCP/UDP ports.

Concept tested: FortiGate application control capabilities and inspection methods

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/526487/application-control

Topics

#Application Control#Security Profiles#Deep Packet Inspection#FortiGate Features

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice