FCP_FGT_AD-7.6 · Question #115
Refer to the exhibit to view the firewall policy. Why would the firewall policy not block a well-known virus, for example eicar?
The correct answer is A. The firewall policy does not apply deep content inspection. The firewall policy uses certificate-inspection under SSL inspection and flow-based inspection mode. Certificate inspection does not decrypt HTTPS traffic; it only checks the certificate fields. Because of this, FortiGate cannot perform deep content inspection, which is…
Question
Refer to the exhibit to view the firewall policy. Why would the firewall policy not block a well-known virus, for example eicar?
Exhibit
Options
- AThe firewall policy does not apply deep content inspection.
- BWeb filter is not enabled on the firewall policy to complement the antivirus profile.
- CThe firewall policy is not configured in proxy-based inspection mode.
- DThe action on the firewall policy is not set to deny.
How the community answered
(48 responses)- A90% (43)
- B2% (1)
- C6% (3)
- D2% (1)
Explanation
The firewall policy uses certificate-inspection under SSL inspection and flow-based inspection mode. Certificate inspection does not decrypt HTTPS traffic; it only checks the certificate fields. Because of this, FortiGate cannot perform deep content inspection, which is required for antivirus to detect and block threats such as the EICAR test virus within encrypted HTTPS sessions.
Topics
Community Discussion
No community discussion yet for this question.
