FCP_FGT_AD-7.6 · Question #112
Refer to the exhibits, which show the firewall policy and an antivirus profile configuration. Why is the user unable to receive a block replacement message when downloading an infected file for the…
The correct answer is A. Flow-based inspection is used, which resets the last packet to the user. In Flow Based scanning, if a virus is detected, the final packet is dropped making the file unusable tot the end user. FG caches the URL of the file. If the user attempts to download again, rather than scanning the file again, the IPS engine then sends a block message to the…
Question
Refer to the exhibits, which show the firewall policy and an antivirus profile configuration. Why is the user unable to receive a block replacement message when downloading an infected file for the first time?
Exhibits
Options
- AFlow-based inspection is used, which resets the last packet to the user.
- BThe option to send files to FortiSandbox for inspection is enabled.
- CThe firewall policy performs a full content inspection on the file.
- DThe intrusion prevention security profile must be enabled when using flow-based inspection
How the community answered
(50 responses)- A80% (40)
- B4% (2)
- C4% (2)
- D12% (6)
Explanation
In Flow Based scanning, if a virus is detected, the final packet is dropped making the file unusable tot the end user. FG caches the URL of the file. If the user attempts to download again, rather than scanning the file again, the IPS engine then sends a block message to the user.
Topics
Community Discussion
No community discussion yet for this question.

