nerdexam
Fortinet

NSE4 · Question #390

Files that are larger than the oversized limit are subjected to which Antivirus check?

The correct answer is C. Sandbox. Files exceeding the configured oversized limit for Antivirus inspection are typically forwarded to a sandbox for detonation and analysis, as they cannot be processed by the FortiGate's local AV engine.

Submitted by noor.lb· Apr 18, 2026Security Profiles and Content Inspection

Question

Files that are larger than the oversized limit are subjected to which Antivirus check?

Options

  • AGrayware
  • BVirus
  • CSandbox
  • DHeuristic

How the community answered

(25 responses)
  • A
    4% (1)
  • C
    92% (23)
  • D
    4% (1)

Why each option

Files exceeding the configured oversized limit for Antivirus inspection are typically forwarded to a sandbox for detonation and analysis, as they cannot be processed by the FortiGate's local AV engine.

AGrayware

Grayware detection is a specific type of AV scanning performed by the FortiGate's local engine, which is bypassed if the file is oversized.

BVirus

Direct virus scanning by the FortiGate's AV engine is skipped for oversized files due to resource limitations.

CSandboxCorrect

When files exceed the FortiGate's configured oversized limit for direct Antivirus scanning, they are often sent to a sandboxing solution, such as FortiSandbox, for deeper, isolated analysis to detect advanced threats without impacting firewall performance.

DHeuristic

Heuristic scanning is a detection method used by the FortiGate's local AV engine and would not be applied to files exceeding the oversized limit.

Concept tested: FortiGate Antivirus oversized file handling

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/990641/oversized-files

Topics

#Antivirus#FortiSandbox#Oversized files#Content Inspection

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice