nerdexam
Fortinet

NSE4 · Question #192

File blocking rules are applied before which of the following?

The correct answer is B. Virus scanning. File blocking rules are applied early in the FortiGate inspection process, specifically before resource-intensive deep content inspection like virus scanning.

Submitted by amina.ke· Apr 18, 2026Security Profiles and Content Inspection

Question

File blocking rules are applied before which of the following?

Options

  • AFirewall policy processing
  • BVirus scanning
  • CWeb URL filtering
  • DWhite/Black list filtering

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    88% (35)
  • C
    3% (1)
  • D
    8% (3)

Why each option

File blocking rules are applied early in the FortiGate inspection process, specifically before resource-intensive deep content inspection like virus scanning.

AFirewall policy processing

Firewall policy processing occurs earlier, determining if traffic is allowed to pass at all, and then subsequent security profiles (including file blocking) are applied if the policy permits.

BVirus scanningCorrect

FortiGate units process traffic through a specific order of inspection. File blocking rules are typically applied before virus scanning to quickly drop files of specific types, reducing the load on the antivirus engine and preventing known undesirable file types from proceeding to deeper, more resource-intensive analysis.

CWeb URL filtering

Web URL filtering, while also a security profile, often occurs in parallel or after initial file blocking as it focuses on destination URLs rather than file content.

DWhite/Black list filtering

White/Black list filtering, such as for email or specific IP addresses, is a different type of filtering that doesn't directly relate to file content inspection order.

Concept tested: FortiGate traffic processing order

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/994488/traffic-processing-order

Topics

#File Blocking#Security Profiles#Inspection Order#UTM Features

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice