nerdexam
Fortinet

FCSS_SASE_AD-25 · Question #54

Refer to the exhibits. A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to…

The correct answer is B. Deep inspection is not enabled. The SSL inspection mode is set to certificate inspection, which only inspects SSL/TLS headers and does not allow full scanning of encrypted content. Without full (deep) inspection, the antivirus profile cannot scan or block malicious files (like eicar.com-zip) delivered over…

Advanced Security Policies

Question

Refer to the exhibits. A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to download the eicar.com-zip file from https://eicar.org. Which configuration on FortiSASE is allowing users to perform the download?

Exhibits

FCSS_SASE_AD-25 question #54 exhibit 1
FCSS_SASE_AD-25 question #54 exhibit 2

Options

  • AWeb filter is allowing the URL.
  • BDeep inspection is not enabled.
  • CApplication control is exempting all the browser traffic.
  • DIntrusion prevention is disabled.

How the community answered

(62 responses)
  • A
    3% (2)
  • B
    74% (46)
  • C
    6% (4)
  • D
    16% (10)

Explanation

The SSL inspection mode is set to certificate inspection, which only inspects SSL/TLS headers and does not allow full scanning of encrypted content. Without full (deep) inspection, the antivirus profile cannot scan or block malicious files (like eicar.com-zip) delivered over HTTPS, allowing the download to proceed.

Topics

#antivirus profile#SSL inspection#EICAR test#security profile group

Community Discussion

No community discussion yet for this question.

Full FCSS_SASE_AD-25 Practice