nerdexam
Fortinet

NSE4 · Question #231

The eicar test virus is put into a zip archive, which is given the password of "Fortinet" in order to open the archive. Review the configuration in the exhibits shown below; then answer the question…

The correct answer is C. Only Exhibit C with default UTM Proxy settings. A DLP profile configured to detect the EICAR string within a password-protected ZIP archive can prevent the file from passing through, assuming default UTM Proxy settings allow for deep content inspection.

Submitted by carter_n· Apr 18, 2026Security Profiles and Content Inspection

Question

The eicar test virus is put into a zip archive, which is given the password of "Fortinet" in order to open the archive. Review the configuration in the exhibits shown below; then answer the question that follows. Exhibit A - Antivirus Profile:

Exhibit B - Non-default UTM Proxy Options Profile:

Exhibit C - DLP Profile:

Which of one the following profiles could be enabled in order to prevent the file from passing through the FortiGate device over HTTP on the standard port for that protocol?

Exhibits

NSE4 question #231 exhibit 1
NSE4 question #231 exhibit 2
NSE4 question #231 exhibit 3

Options

  • AOnly Exhibit A
  • BOnly Exhibit B
  • COnly Exhibit C with default UTM Proxy settings.
  • DAll of the Exhibits (A, B and C)
  • EOnly Exhibit C with non-default UTM Proxy settings (Exhibit B).

How the community answered

(27 responses)
  • A
    7% (2)
  • B
    4% (1)
  • C
    74% (20)
  • D
    15% (4)

Why each option

A DLP profile configured to detect the EICAR string within a password-protected ZIP archive can prevent the file from passing through, assuming default UTM Proxy settings allow for deep content inspection.

AOnly Exhibit A

An Antivirus profile alone cannot typically scan inside a password-protected archive without the password being known or a specific option enabled to handle encrypted archives (e.g., blocking them outright or attempting common passwords), which is not indicated here.

BOnly Exhibit B

The UTM Proxy Options profile defines *how* traffic is processed for inspection (e.g., buffering, timeouts, actions on corrupted files), but it does not perform the content detection or pattern matching itself.

COnly Exhibit C with default UTM Proxy settings.Correct

FortiGate's DLP (Data Loss Prevention) feature is designed to detect specific patterns and content within data streams and files. If a DLP sensor is configured to identify the EICAR test string, it can detect and block the file, even if it is in a password-protected archive, provided the default UTM Proxy settings allow for deep content inspection of compressed or archived files.

DAll of the Exhibits (A, B and C)

Since Antivirus (Exhibit A) is ineffective against password-protected archives without specific configuration, 'All of the Exhibits' cannot be correct.

EOnly Exhibit C with non-default UTM Proxy settings (Exhibit B).

If Exhibit C with default UTM Proxy settings is sufficient, then Exhibit C with *non-default* UTM Proxy settings (Exhibit B) might not be necessary or could introduce unknown variables depending on the non-default settings.

Concept tested: FortiGate Content Inspection (AV, DLP) with Password-Protected Archives

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/526786/data-leak-prevention

Topics

#DLP#Encrypted archives#Content inspection#Security profiles

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice