NSE4 · Question #481
Files reported as "suspicious" were subject to which Antivirus check"?
The correct answer is D. Heuristic. Files reported as 'suspicious' by FortiGate's Antivirus engine are typically identified through heuristic analysis, which detects unknown malware based on suspicious behavior or characteristics.
Question
Files reported as "suspicious" were subject to which Antivirus check"?
Options
- AGrayware
- BVirus
- CSandbox
- DHeuristic
How the community answered
(58 responses)- A2% (1)
- B3% (2)
- C9% (5)
- D86% (50)
Why each option
Files reported as 'suspicious' by FortiGate's Antivirus engine are typically identified through heuristic analysis, which detects unknown malware based on suspicious behavior or characteristics.
Grayware refers to applications that are not malicious but can be intrusive or undesirable, not simply 'suspicious' in the context of a potential virus.
Files identified as an explicit 'virus' would typically match a known signature, not just be flagged as 'suspicious' by heuristic means.
Sandbox analysis is a separate process where suspicious files are executed in an isolated environment to observe their behavior, which might be triggered *after* initial heuristic detection, but 'heuristic' is the direct check that *reports* them as suspicious without execution.
Heuristic scanning is an advanced Antivirus technique that analyzes the behavior and characteristics of files to detect unknown, zero-day, or polymorphic malware that might not match existing signatures. When a file exhibits suspicious behavior but doesn't exactly match a known virus signature, it's often flagged as 'suspicious' by the heuristic engine.
Concept tested: FortiGate Antivirus heuristic analysis
Source: https://docs.fortinet.com/document/fortigate/7.4.0/admin-guide/523098/antivirus-profiles
Topics
Community Discussion
No community discussion yet for this question.