NSE4 · Question #327
Which traffic inspection features can be executed by a security processor (SP)? (Choose three.)
The correct answer is C. Proxy-based antivirus D. Attack signature matching E. Flow-based web filtering. Security Processors (SPs) on FortiGate devices accelerate specific security inspection features, including proxy-based antivirus, attack signature matching, and flow-based web filtering.
Question
Which traffic inspection features can be executed by a security processor (SP)? (Choose three.)
Options
- ATCP SYN proxy
- BSIP session helper
- CProxy-based antivirus
- DAttack signature matching
- EFlow-based web filtering
How the community answered
(48 responses)- A6% (3)
- B13% (6)
- C81% (39)
Why each option
Security Processors (SPs) on FortiGate devices accelerate specific security inspection features, including proxy-based antivirus, attack signature matching, and flow-based web filtering.
TCP SYN proxy is a session helper feature handled by the main CPU, not specifically by security processors for acceleration.
SIP session helper is an application layer gateway (ALG) function, typically processed by the main CPU to manage VoIP traffic, not directly by SPs.
Proxy-based antivirus leverages SPs to offload the compute-intensive scanning of files, enhancing performance for deep inspection.
Attack signature matching, a core component of IPS, is accelerated by SPs to quickly identify and block known threats in network traffic.
Flow-based web filtering benefits from SP acceleration, allowing for efficient categorization and policy enforcement of web traffic based on content and URLs.
Concept tested: FortiGate Security Processor (SP) accelerated features
Source: https://docs.fortinet.com/document/fortigate/7.4.0/hardware-acceleration/208581/overview-of-fortigate-soc4-and-soc5-features
Topics
Community Discussion
No community discussion yet for this question.