nerdexam
Fortinet

NSE4 · Question #536

How do you configure inline SSL inspection on a firewall policy? (Choose two.)

The correct answer is A. Enable one or more flow-based security profiles on the firewall policy. B. Enable the SSL/SSH Inspection profile on the firewall policy.. To configure inline SSL inspection on a FortiGate firewall policy, you must enable an SSL/SSH Inspection profile and then apply one or more flow-based security profiles.

Submitted by tarun92· Apr 18, 2026Security Profiles and Content Inspection

Question

How do you configure inline SSL inspection on a firewall policy? (Choose two.)

Options

  • AEnable one or more flow-based security profiles on the firewall policy.
  • BEnable the SSL/SSH Inspection profile on the firewall policy.
  • CExecute the inline ssl inspection CLI command.
  • DEnable one or more proxy-based security profiles on the firewall policy.

How the community answered

(29 responses)
  • A
    97% (28)
  • C
    3% (1)

Why each option

To configure inline SSL inspection on a FortiGate firewall policy, you must enable an SSL/SSH Inspection profile and then apply one or more flow-based security profiles.

AEnable one or more flow-based security profiles on the firewall policy.Correct

Inline SSL inspection works with flow-based inspection mode; once an SSL/SSH Inspection profile is enabled, applying flow-based security profiles allows these engines to inspect the decrypted traffic.

BEnable the SSL/SSH Inspection profile on the firewall policy.Correct

The SSL/SSH Inspection profile is the foundational component that enables the FortiGate to decrypt and re-encrypt SSL/TLS traffic, making it inspectable by other security profiles.

CExecute the inline ssl inspection CLI command.

There is no single `inline ssl inspection CLI command` that enables and configures the feature on a policy; it is a combination of profile application within the firewall policy configuration.

DEnable one or more proxy-based security profiles on the firewall policy.

Inline SSL inspection is inherently designed to work with *flow-based* inspection, not proxy-based inspection, which operates differently and typically involves a full proxy for Layer 7 analysis.

Concept tested: FortiGate inline SSL inspection configuration

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/526725/ssl-ssh-inspection

Topics

#SSL Inspection#Firewall Policies#Security Profiles#Flow-based Inspection

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice