FCSS_SASE_AD-25 · Question #54
Refer to the exhibits. A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to…
The correct answer is B. Deep inspection is not enabled. The SSL inspection mode is set to certificate inspection, which only inspects SSL/TLS headers and does not allow full scanning of encrypted content. Without full (deep) inspection, the antivirus profile cannot scan or block malicious files (like eicar.com-zip) delivered over…
Question
Refer to the exhibits. A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to download the eicar.com-zip file from https://eicar.org. Which configuration on FortiSASE is allowing users to perform the download?
Exhibits
Options
- AWeb filter is allowing the URL.
- BDeep inspection is not enabled.
- CApplication control is exempting all the browser traffic.
- DIntrusion prevention is disabled.
How the community answered
(62 responses)- A3% (2)
- B74% (46)
- C6% (4)
- D16% (10)
Explanation
The SSL inspection mode is set to certificate inspection, which only inspects SSL/TLS headers and does not allow full scanning of encrypted content. Without full (deep) inspection, the antivirus profile cannot scan or block malicious files (like eicar.com-zip) delivered over HTTPS, allowing the download to proceed.
Topics
Community Discussion
No community discussion yet for this question.

