nerdexam
Fortinet

FCP_FGT_AD-7.6 · Question #40

A network administrator enabled antivirus and selected an SSL inspection profile on a firewall policy. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the…

The correct answer is A. The selected SSL inspection profile has certificate inspection enabled. B. The website is exempted from SSL inspection. Certificate inspection is not deep ssl inspection hence no inspection of the packet would happen since it is encrypted. If the https site is in exampted list then yes it is a valid reason.

Submitted by yasin.bd· Apr 18, 2026Content inspection

Question

A network administrator enabled antivirus and selected an SSL inspection profile on a firewall policy. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and does not block the file, allowing it to be downloaded. The administrator confirms that the traffic matches the configured firewall policy. What are two reasons for the failed virus detection by FortiGate? (Choose two.)

Options

  • AThe selected SSL inspection profile has certificate inspection enabled.
  • BThe website is exempted from SSL inspection.
  • CThe El CAR test file exceeds the protocol options oversize limit.
  • DThe browser does not trust the FortiGate self-signed CA certificate.

How the community answered

(39 responses)
  • A
    79% (31)
  • C
    8% (3)
  • D
    13% (5)

Explanation

Certificate inspection is not deep ssl inspection hence no inspection of the packet would happen since it is encrypted. If the https site is in exampted list then yes it is a valid reason.

Topics

#SSL Inspection#Certificate Inspection#SSL Exemption#Antivirus

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.6 Practice