NSE4 · Question #231
The eicar test virus is put into a zip archive, which is given the password of "Fortinet" in order to open the archive. Review the configuration in the exhibits shown below; then answer the question…
The correct answer is C. Only Exhibit C with default UTM Proxy settings. A DLP profile configured to detect the EICAR string within a password-protected ZIP archive can prevent the file from passing through, assuming default UTM Proxy settings allow for deep content inspection.
Question
The eicar test virus is put into a zip archive, which is given the password of "Fortinet" in order to open the archive. Review the configuration in the exhibits shown below; then answer the question that follows. Exhibit A - Antivirus Profile:
Exhibit B - Non-default UTM Proxy Options Profile:
Exhibit C - DLP Profile:
Which of one the following profiles could be enabled in order to prevent the file from passing through the FortiGate device over HTTP on the standard port for that protocol?
Exhibits
Options
- AOnly Exhibit A
- BOnly Exhibit B
- COnly Exhibit C with default UTM Proxy settings.
- DAll of the Exhibits (A, B and C)
- EOnly Exhibit C with non-default UTM Proxy settings (Exhibit B).
How the community answered
(27 responses)- A7% (2)
- B4% (1)
- C74% (20)
- D15% (4)
Why each option
A DLP profile configured to detect the EICAR string within a password-protected ZIP archive can prevent the file from passing through, assuming default UTM Proxy settings allow for deep content inspection.
An Antivirus profile alone cannot typically scan inside a password-protected archive without the password being known or a specific option enabled to handle encrypted archives (e.g., blocking them outright or attempting common passwords), which is not indicated here.
The UTM Proxy Options profile defines *how* traffic is processed for inspection (e.g., buffering, timeouts, actions on corrupted files), but it does not perform the content detection or pattern matching itself.
FortiGate's DLP (Data Loss Prevention) feature is designed to detect specific patterns and content within data streams and files. If a DLP sensor is configured to identify the EICAR test string, it can detect and block the file, even if it is in a password-protected archive, provided the default UTM Proxy settings allow for deep content inspection of compressed or archived files.
Since Antivirus (Exhibit A) is ineffective against password-protected archives without specific configuration, 'All of the Exhibits' cannot be correct.
If Exhibit C with default UTM Proxy settings is sufficient, then Exhibit C with *non-default* UTM Proxy settings (Exhibit B) might not be necessary or could introduce unknown variables depending on the non-default settings.
Concept tested: FortiGate Content Inspection (AV, DLP) with Password-Protected Archives
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/526786/data-leak-prevention
Topics
Community Discussion
No community discussion yet for this question.


