nerdexam
Fortinet

NSE4 · Question #481

Files reported as "suspicious" were subject to which Antivirus check"?

The correct answer is D. Heuristic. Files reported as 'suspicious' by FortiGate's Antivirus engine are typically identified through heuristic analysis, which detects unknown malware based on suspicious behavior or characteristics.

Submitted by luis.pe· Apr 18, 2026Security Profiles and Content Inspection

Question

Files reported as "suspicious" were subject to which Antivirus check"?

Options

  • AGrayware
  • BVirus
  • CSandbox
  • DHeuristic

How the community answered

(58 responses)
  • A
    2% (1)
  • B
    3% (2)
  • C
    9% (5)
  • D
    86% (50)

Why each option

Files reported as 'suspicious' by FortiGate's Antivirus engine are typically identified through heuristic analysis, which detects unknown malware based on suspicious behavior or characteristics.

AGrayware

Grayware refers to applications that are not malicious but can be intrusive or undesirable, not simply 'suspicious' in the context of a potential virus.

BVirus

Files identified as an explicit 'virus' would typically match a known signature, not just be flagged as 'suspicious' by heuristic means.

CSandbox

Sandbox analysis is a separate process where suspicious files are executed in an isolated environment to observe their behavior, which might be triggered *after* initial heuristic detection, but 'heuristic' is the direct check that *reports* them as suspicious without execution.

DHeuristicCorrect

Heuristic scanning is an advanced Antivirus technique that analyzes the behavior and characteristics of files to detect unknown, zero-day, or polymorphic malware that might not match existing signatures. When a file exhibits suspicious behavior but doesn't exactly match a known virus signature, it's often flagged as 'suspicious' by the heuristic engine.

Concept tested: FortiGate Antivirus heuristic analysis

Source: https://docs.fortinet.com/document/fortigate/7.4.0/admin-guide/523098/antivirus-profiles

Topics

#Antivirus#Heuristic scanning#Malware detection

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice