nerdexam
Fortinet

NSE4 · Question #539

An administrator has blocked Netflix login in a cloud access security inspection (CASI) profile. The administrator has also applied the CASI profile to a firewall policy. What else is required for the

The correct answer is C. You must apply an application control profile to the firewall policy.. For a Cloud Access Security Inspection (CASI) profile to effectively block specific cloud application actions like Netflix login, an application control profile must be applied to the firewall policy.

Submitted by carter_n· Apr 18, 2026Security Profiles and Content Inspection

Question

An administrator has blocked Netflix login in a cloud access security inspection (CASI) profile. The administrator has also applied the CASI profile to a firewall policy. What else is required for the CASI profile to work properly?

Options

  • AYou must enable logging for security events on the firewall policy.
  • BYou must activate a FortiCloud account.
  • CYou must apply an application control profile to the firewall policy.
  • DYou must enable SSL inspection on the firewall policy.

How the community answered

(30 responses)
  • A
    10% (3)
  • B
    3% (1)
  • C
    83% (25)
  • D
    3% (1)

Why each option

For a Cloud Access Security Inspection (CASI) profile to effectively block specific cloud application actions like Netflix login, an application control profile must be applied to the firewall policy.

AYou must enable logging for security events on the firewall policy.

Logging for security events is important for monitoring and auditing but is not a functional requirement for the CASI profile itself to inspect and block traffic.

BYou must activate a FortiCloud account.

Activating a FortiCloud account provides management and services but is not a prerequisite for the basic functionality of a CASI profile on the FortiGate appliance.

CYou must apply an application control profile to the firewall policy.Correct

CASI profiles rely on the underlying Application Control engine to identify and categorize specific cloud applications and their functions, meaning an application control profile must be applied to the firewall policy for CASI rules to take effect.

DYou must enable SSL inspection on the firewall policy.

While SSL inspection is typically necessary for deep inspection of encrypted traffic to detect granular application actions, the most direct profile dependency for the CASI logic to operate is the Application Control profile.

Concept tested: FortiGate CASI profile dependencies

Source: https://docs.fortinet.com/document/fortigate/7.0.0/administration-guide/33924/casb-access-control

Topics

#CASI#Application Control#Security Profiles#Firewall Policy

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice