nerdexam
Fortinet

FCP_FGT_AD-7.4 · Question #20

Refer to the exhibits, which show the firewall policy and an antivirus profile configuration. Why is the user unable to receive a block replacement message when downloading an infected file for the…

The correct answer is D. Flow-based inspection is used, which resets the last packet to the user. In flow-based inspection mode, FortiGate sends a reset (RST) packet to the client instead of providing a replacement message, which causes the block message not to be displayed.

Content inspection

Question

Refer to the exhibits, which show the firewall policy and an antivirus profile configuration. Why is the user unable to receive a block replacement message when downloading an infected file for the first time?

Exhibit

FCP_FGT_AD-7.4 question #20 exhibit

Options

  • AThe intrusion prevention security profile must be enabled when using flow-based inspection
  • BThe option to send files to FortiSandbox for inspection is enabled.
  • CThe firewall policy performs a full content inspection on the file.
  • DFlow-based inspection is used, which resets the last packet to the user.

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    8% (3)
  • C
    3% (1)
  • D
    84% (31)

Explanation

In flow-based inspection mode, FortiGate sends a reset (RST) packet to the client instead of providing a replacement message, which causes the block message not to be displayed.

Topics

#antivirus#flow-based inspection#block replacement message#packet reset

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.4 Practice