nerdexam
Fortinet

NSE4 · Question #68

Which statements are true about offloading antivirus inspection to a Security Processor (SP)? (Choose two.)

The correct answer is B. A replacement message cannot be presented to users when a virus has been detected. C. It saves CPU resources.. This question addresses the capabilities and limitations of offloading antivirus inspection to a FortiGate Security Processor (SP).

Submitted by omar99· Apr 18, 2026Security Profiles and Content Inspection

Question

Which statements are true about offloading antivirus inspection to a Security Processor (SP)? (Choose two.)

Options

  • ABoth proxy-based and flow-based inspection are supported.
  • BA replacement message cannot be presented to users when a virus has been detected.
  • CIt saves CPU resources.
  • DThe ingress and egress interfaces can be in different SPs.

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    84% (16)
  • D
    11% (2)

Why each option

This question addresses the capabilities and limitations of offloading antivirus inspection to a FortiGate Security Processor (SP).

ABoth proxy-based and flow-based inspection are supported.

Security Processors primarily support offloading for flow-based inspection, but deep, proxy-based inspection for antivirus often requires main CPU involvement and cannot be fully offloaded to an SP.

BA replacement message cannot be presented to users when a virus has been detected.Correct

When antivirus inspection is offloaded to a Security Processor (SP), the SP typically handles the scanning efficiently but usually lacks the capability to generate and present custom replacement messages to users upon virus detection, often resulting in a dropped file.

CIt saves CPU resources.Correct

Offloading computationally intensive tasks like antivirus inspection to a dedicated Security Processor is primarily done to reduce the load on the main FortiGate CPU, thereby saving CPU resources and enhancing overall performance.

DThe ingress and egress interfaces can be in different SPs.

For hardware offloading by an SP, both the ingress and egress interfaces for a traffic flow typically need to reside within the domain of the same SP to allow for continuous acceleration; traffic spanning different SPs often falls back to the main CPU.

Concept tested: FortiGate Security Processor antivirus offloading

Source: https://docs.fortinet.com/document/fortigate/7.4.0/hardware-acceleration/258597/cp9-offloading-capabilities

Topics

#Antivirus Inspection#Hardware Offloading#Security Processor#Performance Optimization

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice