FCP_FGT_AD-7.6 · Question #6
Which three statements explain a flow-based antivirus profile? (Choose three.)
The correct answer is A. FortiGate buffers the whole file but transmits to the client at the same time. B. Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection. D. Flow-based inspection optimizes performance compared to proxy-based inspection. Three true statements about flow-based antivirus profiles in FortiGate are: (A) FortiGate buffers the entire file while simultaneously forwarding packets to the client - this is the defining characteristic of flow-based inspection; it does not hold traffic until the full scan…
Question
Which three statements explain a flow-based antivirus profile? (Choose three.)
Options
- AFortiGate buffers the whole file but transmits to the client at the same time.
- BFlow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection.
- CIf a virus is detected, the last packet is delivered to the client.
- DFlow-based inspection optimizes performance compared to proxy-based inspection.
- EThe IPS engine handles the process as a standalone.
How the community answered
(29 responses)- A90% (26)
- C7% (2)
- E3% (1)
Explanation
Three true statements about flow-based antivirus profiles in FortiGate are: (A) FortiGate buffers the entire file while simultaneously forwarding packets to the client - this is the defining characteristic of flow-based inspection; it does not hold traffic until the full scan completes (unlike proxy-based), which improves user experience at the cost of potentially delivering a file before a verdict is reached; (B) Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection, combining techniques to achieve a balance of performance and detection; and (D) Flow-based inspection optimizes performance compared to proxy-based because it does not fully buffer and hold sessions, reducing latency and resource usage. Option C is false - if a virus is detected, the last packet is dropped, not delivered. Option E is false - in flow-based mode, the IPS engine does not operate as a standalone; it works in conjunction with the antivirus scanning engine.
Topics
Community Discussion
No community discussion yet for this question.