Reviewing the utility's overall content-inspection design, an auditor asks why the billing segment uses deep inspection with full antivirus and web filtering, the substation segment uses certificate inspection with an SSL exemption for the OT vendor's pinned application, and the NOC administrator segment uses deep inspection plus a distributed trusted CA certificate. What principle best explains why these three segments are configured differently rather than sharing one SSL/SSH inspection profile?
Select an answer to reveal the explanation.
Short Explanation
A one-size-fits-all inspection policy ignores that not all traffic behaves the same way. Billing traffic can tolerate full decryption, the OT vendor's app can't tolerate any certificate substitution, and NOC admin traffic needs deep inspection paired with properly trusted certificates to avoid warnings. Matching each segment's SSL/SSH profile to its actual needs is exactly the design FortiGate supports and exactly what this utility built.
Full Explanation
FortiOS allows a distinct SSL/SSH inspection profile to be assigned per firewall policy, which is precisely what lets an administrator tailor inspection depth to each segment's actual traffic and risk profile instead of forcing one setting on everything. The billing segment's general web traffic tolerates full decryption, so deep inspection there maximizes antivirus and web-filtering coverage. The OT vendor's substation application cannot tolerate certificate substitution at all, so certificate inspection plus a targeted exemption preserves both partial visibility and application functionality. The NOC administrator segment needs full content visibility too, but because it also involves administrator workstations that can be centrally managed, deep inspection is paired with proper CA certificate distribution to avoid the trust warnings seen elsewhere in this scenario. None of this reflects a device-wide limit — multiple SSL/SSH inspection profiles can exist and be assigned independently across policies, so the 'one profile per device' claim is false. Deep inspection availability is not gated by a segment-count license restriction in the way described. SD-WAN link latency has no bearing on which SSL/SSH inspection profile a policy uses; that assignment is an administrator choice at the firewall-policy level, not something SD-WAN infers automatically. To audit this design, review each policy's assigned SSL/SSH inspection profile individually and confirm the choice is documented and justified by that segment's actual traffic and constraints rather than left to default settings.