nerdexam
Fortinet

NSE4_FGT_AD-7.6 · Question #35

A network administrator enabled antivirus and selected an SSL inspection profile on a firewall policy. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the…

The correct answer is A. The selected SSL inspection profile has certificate inspection enabled. B. The website is exempted from SSL inspection. Certificate inspection is not deep ssl inspection hence no inspection of the packet would happen since it is encrypted. If the https site is in exempted list then yes it is a valid reason.

Security Profiles

Question

A network administrator enabled antivirus and selected an SSL inspection profile on a firewall policy. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and does not block the file, allowing it to be downloaded. The administrator confirms that the traffic matches the configured firewall policy. What are two reasons for the failed virus detection by FortiGate? (Choose two.)

Options

  • AThe selected SSL inspection profile has certificate inspection enabled.
  • BThe website is exempted from SSL inspection.
  • CThe EICAR test file exceeds the protocol options oversize limit.
  • DThe browser does not trust the FortiGate self-signed CA certificate.

How the community answered

(41 responses)
  • A
    80% (33)
  • C
    12% (5)
  • D
    7% (3)

Explanation

Certificate inspection is not deep ssl inspection hence no inspection of the packet would happen since it is encrypted. If the https site is in exempted list then yes it is a valid reason.

Topics

#antivirus#SSL inspection#certificate inspection#HTTPS scanning

Community Discussion

No community discussion yet for this question.

Full NSE4_FGT_AD-7.6 Practice