nerdexam
Fortinet

NSE4 · Question #488

Which of the following statements are true regarding application control? (Choose two.)

The correct answer is C. Encrypted traffic can be identified by application control. D. Traffic shaping can be applied to the detected application traffic. FortiGate Application Control can identify and manage encrypted traffic through deep packet inspection, and it allows for traffic shaping to prioritize or limit detected application flows.

Submitted by lars.no· Apr 18, 2026Security Profiles and Content Inspection

Question

Which of the following statements are true regarding application control? (Choose two.)

Options

  • AApplication control is based on TCP destination port numbers.
  • BApplication control is proxy based.
  • CEncrypted traffic can be identified by application control.
  • DTraffic shaping can be applied to the detected application traffic.

How the community answered

(68 responses)
  • A
    1% (1)
  • B
    4% (3)
  • C
    94% (64)

Why each option

FortiGate Application Control can identify and manage encrypted traffic through deep packet inspection, and it allows for traffic shaping to prioritize or limit detected application flows.

AApplication control is based on TCP destination port numbers.

Application control relies on deep packet inspection and behavioral analysis to identify applications, going beyond simple TCP destination port numbers, as applications can use non-standard ports.

BApplication control is proxy based.

While proxies can perform application-level analysis, FortiGate's Application Control primarily operates using flow-based deep packet inspection rather than being strictly proxy-based.

CEncrypted traffic can be identified by application control.Correct

FortiGate Application Control leverages advanced techniques like deep packet inspection and heuristic analysis to identify applications, even when their traffic is encrypted, by analyzing behavioral patterns and flow characteristics without full decryption.

DTraffic shaping can be applied to the detected application traffic.Correct

Traffic shaping profiles can be directly applied to specific application traffic identified by Application Control within FortiGate firewall policies, allowing administrators to prioritize, limit, or guarantee bandwidth for various applications.

Concept tested: FortiGate Application Control capabilities

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/378401/application-control

Topics

#Application Control#Traffic Shaping#Encrypted Traffic Inspection#FortiGate Security Profiles

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice