nerdexam
Fortinet

FCSS_SASE_AD-24 · Question #16

Refer to the exhibits. A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to…

The correct answer is D. Force certificate inspection is enabled in the policy. https://community.fortinet.com/t5/FortiSASE/Technical-Tip-Force-Certificate-Inspection-option-in- FortiSASE/ta-p/302617

Security Profiles and Policies

Question

Refer to the exhibits. A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to download the eicar.com-zip file from https://eicar.org. Traffic logs show traffic is allowed by the policy. Which configuration on FortiSASE is allowing users to perform the download?

Exhibits

FCSS_SASE_AD-24 question #16 exhibit 1
FCSS_SASE_AD-24 question #16 exhibit 2

Options

  • AWeb filter is allowing the traffic.
  • BIPS is disabled in the security profile group.
  • CThe HTTPS protocol is not enabled in the antivirus profile.
  • DForce certificate inspection is enabled in the policy.

How the community answered

(48 responses)
  • A
    15% (7)
  • B
    4% (2)
  • C
    6% (3)
  • D
    75% (36)

Explanation

https://community.fortinet.com/t5/FortiSASE/Technical-Tip-Force-Certificate-Inspection-option-in- FortiSASE/ta-p/302617

Topics

#antivirus profile#certificate inspection#SSL deep inspection#HTTPS scanning

Community Discussion

No community discussion yet for this question.

Full FCSS_SASE_AD-24 Practice