nerdexam
Fortinet

NSE4 · Question #482

Which profile could IPS engine use on an interface that is in sniffer mode? (Choose three)

The correct answer is A. Antivirus (flow based B. Web filtering (PROXY BASED) D. Application Control. When an interface is in sniffer mode, the IPS engine can use flow-based Antivirus, Intrusion Protection, and Application Control profiles to monitor and detect threats from mirrored traffic.

Submitted by thandi_sa· Apr 18, 2026Security Profiles and Content Inspection

Question

Which profile could IPS engine use on an interface that is in sniffer mode? (Choose three)

Options

  • AAntivirus (flow based
  • BWeb filtering (PROXY BASED)
  • CIntrusion Protection
  • DApplication Control
  • EEndpoint control

How the community answered

(39 responses)
  • A
    74% (29)
  • C
    18% (7)
  • E
    8% (3)

Why each option

When an interface is in sniffer mode, the IPS engine can use flow-based Antivirus, Intrusion Protection, and Application Control profiles to monitor and detect threats from mirrored traffic.

AAntivirus (flow basedCorrect

Flow-based Antivirus profiles can inspect traffic as it passes through the FortiGate in sniffer mode, identifying and reporting malware without blocking.

BWeb filtering (PROXY BASED)Correct
CIntrusion Protection
DApplication ControlCorrect

Application Control profiles can identify and report on application usage within the network traffic being sniffed, providing visibility into what applications are running.

EEndpoint control

Endpoint control typically involves direct communication and management of endpoints, which is an active function not suited for a passive sniffer interface.

Concept tested: FortiGate sniffer mode security profiles

Source: https://docs.fortinet.com/document/fortigate/7.4.0/admin-guide/869094/interface-modes

Topics

#Security Profiles#Content Inspection#Sniffer Mode#FortiGate

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice