NSE4 · Question #390
Files that are larger than the oversized limit are subjected to which Antivirus check?
The correct answer is C. Sandbox. Files exceeding the configured oversized limit for Antivirus inspection are typically forwarded to a sandbox for detonation and analysis, as they cannot be processed by the FortiGate's local AV engine.
Question
Files that are larger than the oversized limit are subjected to which Antivirus check?
Options
- AGrayware
- BVirus
- CSandbox
- DHeuristic
How the community answered
(25 responses)- A4% (1)
- C92% (23)
- D4% (1)
Why each option
Files exceeding the configured oversized limit for Antivirus inspection are typically forwarded to a sandbox for detonation and analysis, as they cannot be processed by the FortiGate's local AV engine.
Grayware detection is a specific type of AV scanning performed by the FortiGate's local engine, which is bypassed if the file is oversized.
Direct virus scanning by the FortiGate's AV engine is skipped for oversized files due to resource limitations.
When files exceed the FortiGate's configured oversized limit for direct Antivirus scanning, they are often sent to a sandboxing solution, such as FortiSandbox, for deeper, isolated analysis to detect advanced threats without impacting firewall performance.
Heuristic scanning is a detection method used by the FortiGate's local AV engine and would not be applied to files exceeding the oversized limit.
Concept tested: FortiGate Antivirus oversized file handling
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/990641/oversized-files
Topics
Community Discussion
No community discussion yet for this question.