nerdexam
Fortinet

NSE7_SSE_AD-25 · Question #54

Refer to the exhibits. A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to…

The correct answer is B. Deep inspection is not enabled. The SSL inspection mode is set to certificate inspection, which only inspects SSL/TLS headers and does not allow full scanning of encrypted content. Without full (deep) inspection, the antivirus profile cannot scan or block malicious files (like eicar.com-zip) delivered over…

FortiSASE Secure Web Gateway (SWG)

Question

Refer to the exhibits. A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to download the eicar.com-zip file from https://eicar.org. Which configuration on FortiSASE is allowing users to perform the download?

Exhibits

NSE7_SSE_AD-25 question #54 exhibit 1
NSE7_SSE_AD-25 question #54 exhibit 2

Options

  • AWeb filter is allowing the URL.
  • BDeep inspection is not enabled.
  • CApplication control is exempting all the browser traffic.
  • DIntrusion prevention is disabled.

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    71% (17)
  • C
    8% (2)
  • D
    17% (4)

Explanation

The SSL inspection mode is set to certificate inspection, which only inspects SSL/TLS headers and does not allow full scanning of encrypted content. Without full (deep) inspection, the antivirus profile cannot scan or block malicious files (like eicar.com-zip) delivered over HTTPS, allowing the download to proceed.

Topics

#antivirus profile#deep inspection#SSL inspection bypass#security profiles

Community Discussion

No community discussion yet for this question.

Full NSE7_SSE_AD-25 Practice