nerdexam
Fortinet

FCP_FGT_AD-7.6 · Question #112

Refer to the exhibits, which show the firewall policy and an antivirus profile configuration. Why is the user unable to receive a block replacement message when downloading an infected file for the…

The correct answer is A. Flow-based inspection is used, which resets the last packet to the user. In Flow Based scanning, if a virus is detected, the final packet is dropped making the file unusable tot the end user. FG caches the URL of the file. If the user attempts to download again, rather than scanning the file again, the IPS engine then sends a block message to the…

Submitted by joshua94· Apr 18, 2026Content inspection

Question

Refer to the exhibits, which show the firewall policy and an antivirus profile configuration. Why is the user unable to receive a block replacement message when downloading an infected file for the first time?

Exhibits

FCP_FGT_AD-7.6 question #112 exhibit 1
FCP_FGT_AD-7.6 question #112 exhibit 2

Options

  • AFlow-based inspection is used, which resets the last packet to the user.
  • BThe option to send files to FortiSandbox for inspection is enabled.
  • CThe firewall policy performs a full content inspection on the file.
  • DThe intrusion prevention security profile must be enabled when using flow-based inspection

How the community answered

(50 responses)
  • A
    80% (40)
  • B
    4% (2)
  • C
    4% (2)
  • D
    12% (6)

Explanation

In Flow Based scanning, if a virus is detected, the final packet is dropped making the file unusable tot the end user. FG caches the URL of the file. If the user attempts to download again, rather than scanning the file again, the IPS engine then sends a block message to the user.

Topics

#FortiGate Antivirus#Flow-based inspection#Block replacement message#Content inspection

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.6 Practice