nerdexam
Fortinet

NSE4 · Question #551

Which statements about FortiGate inspection modes are true? (Choose two.)

The correct answer is A. The default inspection mode is proxy based. C. Proxy-based inspection is not available in VDOMs operating in transparent mode. The default inspection mode on FortiGate is proxy-based, but proxy-based inspection is not supported in VDOMs operating in transparent mode.

Submitted by wei.xz· Apr 18, 2026Security Profiles and Content Inspection

Question

Which statements about FortiGate inspection modes are true? (Choose two.)

Options

  • AThe default inspection mode is proxy based.
  • BSwitching from proxy-based mode to flow-based, then back to proxy-based mode, will not result in the
  • CProxy-based inspection is not available in VDOMs operating in transparent mode.
  • DFlow-based profiles must be manually converted to proxy-based profiles before changing the

How the community answered

(49 responses)
  • A
    90% (44)
  • B
    4% (2)
  • D
    6% (3)

Why each option

The default inspection mode on FortiGate is proxy-based, but proxy-based inspection is not supported in VDOMs operating in transparent mode.

AThe default inspection mode is proxy based.Correct

By default, newly provisioned FortiGates and VDOMs operate in proxy-based inspection mode, offering full content inspection and buffering.

BSwitching from proxy-based mode to flow-based, then back to proxy-based mode, will not result in the

Switching between inspection modes, especially from proxy-based to flow-based and back, can indeed affect existing profiles or policies, potentially requiring review and adjustment.

CProxy-based inspection is not available in VDOMs operating in transparent mode.Correct

VDOMs operating in transparent mode (Layer 2 bridge) are limited to flow-based inspection because transparent bridging does not perform the full proxy operations required for proxy-based inspection.

DFlow-based profiles must be manually converted to proxy-based profiles before changing the

FortiGate automatically converts inspection profiles when the inspection mode of the VDOM or device is changed, although manual review and adjustments might still be necessary.

Concept tested: FortiGate Inspection Modes (Proxy vs. Flow) and VDOMs

Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-administration-guide/575308/inspection-modes

Topics

#Inspection Modes#Proxy-based#Flow-based#VDOM Transparent Mode

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice