Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE4_FGT_AD-7.6 Exam - Topic 4 Question 7 Discussion

Which three statements explain a flow-based antivirus profile? (Choose three answers)
A) FortiGate buffers the whole file but transmits to the client at the same time. and B) Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection. and D) Flow-based inspection optimizes performance compared to proxy-based inspection.
C) If a virus is detected, the last packet is delivered to the client.
E) The IPS engine handles the process as a standalone.

Fortinet NSE4_FGT_AD-7.6 Exam - Topic 4 Question 7 Discussion

Actual exam question for Fortinet's NSE4_FGT_AD-7.6 exam
Question #: 7
Topic #: 4
[All NSE4_FGT_AD-7.6 Questions]

Which three statements explain a flow-based antivirus profile? (Choose three answers)

Show Suggested Answer Hide Answer
Suggested Answer: A, B, D

According to the FortiOS 7.6 Study Guide and Parallel Path Processing documentation, flow-based antivirus inspection is designed to provide security with minimal impact on performance.

First, a defining characteristic of modern flow-based AV (specifically in its 'hybrid' mode) is that FortiGate buffers the whole file but transmits to the client at the same time (Statement A). This behavior allows the client to start receiving data immediately to prevent session timeouts, while the FortiGate reassembles the file in memory to perform a signature check before the final packet is released.

Second, starting with recent FortiOS versions including 7.6, flow-based inspection uses a hybrid of the scanning modes (Statement B). Previously, flow mode offered 'Quick' or 'Full' scans; now, it combines these techniques to offer a balance between the speed of stream-based scanning and the thoroughness of archive inspection.

Third, the primary motivation for selecting this mode is that flow-based inspection optimizes performance compared to proxy-based inspection (Statement D). It processes traffic in a single pass using the IPS engine, avoiding the overhead associated with the WAD (proxy) process. Statement C is incorrect because if a virus is detected, the last packet is withheld and the connection is reset to prevent the file from being completed. Statement E is less accurate as the IPS engine loads the AV engine to perform the task rather than acting as a 'standalone' entity in the context of file scanning.


Contribute your Thoughts:

0/2000 characters
Avery
3 hours ago
Agreed! D makes sense. I also feel B is right. Hybrid scanning is smart.
upvoted 0 times
...
Bernardo
5 days ago
I think D is definitely one of the answers. Performance is key!
upvoted 0 times
...
Tammara
10 days ago
E) seems off, the IPS is usually integrated.
upvoted 0 times
...
Dyan
16 days ago
Totally agree with D), flow-based is way faster.
upvoted 0 times
...
Micah
2 months ago
Surprised that C) is even an option!
upvoted 0 times
...
Freida
2 months ago
I think B) is a bit misleading, though.
upvoted 0 times
...
Pansy
2 months ago
A) and D) are definitely true!
upvoted 0 times
...
Shay
3 months ago
E doesn't really fit with flow-based, I think.
upvoted 0 times
...
Daniel
3 months ago
Wait, so the last packet gets sent even if a virus is found? That’s surprising!
upvoted 0 times
...
Irma
3 months ago
B is definitely true, love the hybrid approach!
upvoted 0 times
...
Annabelle
3 months ago
I disagree with C, that doesn't sound right.
upvoted 0 times
...
Lyla
3 months ago
A) and D) are spot on!
upvoted 0 times
...
Rima
3 months ago
I practiced a similar question, and I think C is misleading because I don't remember packets being delivered if a virus is found.
upvoted 0 times
...
Junita
4 months ago
I feel like B might be right too, but I need to double-check how hybrid scanning works in flow-based profiles.
upvoted 0 times
...
Cecily
4 months ago
I'm a bit unsure about A; I remember something about buffering but can't recall the details.
upvoted 0 times
...
Alline
4 months ago
I think option D is definitely correct since flow-based inspection is supposed to be faster than proxy-based.
upvoted 0 times
...

Save Cancel