NSE4 Security Profiles Practice Question
A FortiGate administrator wants to integrate with FortiSandbox to analyze suspicious files detected by antivirus. The administrator configures the FortiSandbox settings under Security Fabric. However, files are not being sent to FortiSandbox. The antivirus profile is set to 'flow-based' inspection. What could be the reason?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Flow-based inspection does not support FortiSandbox integration; proxy-based inspection is required.
The distinction between flow-based and proxy-based inspection is fundamental to understanding FortiSandbox integration. In proxy mode, FortiGate acts as an explicit proxy for the traffic, receiving the entire file, reassembling it, and then deciding to forward it to FortiSandbox for in-depth analysis. In flow mode, packets are inspected as they pass through with a streamlined engine optimized for throughput, which prevents the FortiGate from holding back the full file for upload. FortiSandbox integration in flow mode is limited to 'FortiSandbox outbreak prevention', which performs a hash lookup against the FortiSandbox cloud or appliance cache, but cannot submit unknown files. This is a common misconfiguration: administrators assume that simply enabling FortiSandbox on the security profile is sufficient, but the firewall policy must be set to proxy-based inspection. Understanding this distinction is crucial for passing NSE4 topics on advanced threat protection, as well as for real-world deployments where traffic volume might tempt an admin to use flow mode only to discover that sandboxing silently stops working.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The antivirus profile is set to 'Monitor' instead of 'Block'.
Why it's wrong here
Setting the antivirus profile to 'Monitor' only changes the local log-and-permit behavior for detected malware; it does not control whether files are sent to FortiSandbox. In proxy-based inspection, FortiGate forwards files to FortiSandbox for analysis regardless of the AV action — even a 'Monitor' action still triggers sandbox submission. Thus, this setting would not prevent the FortiGate from integrating with or communicating with FortiSandbox.
- ✗
The firewall policy is using NAT, which interferes with FortiSandbox connectivity.
Why it's wrong here
Network Address Translation (NAT) is applied to outbound sessions on the FortiGate and does not block or interfere with the FortiGate's own management-plane connection to FortiSandbox. FortiSandbox integration uses a dedicated tunnel or HTTPS session initiated from the FortiGate itself, and as long as there is a viable route and the necessary TCP ports are allowed, NAT is transparent. Therefore, a firewall policy using NAT would not be the reason FortiSandbox integration fails.
- ✗
The FortiGate does not have a valid FortiSandbox license.
Why it's wrong here
Although a FortiSandbox license is normally required to enable the integration, the scenario explicitly states that the integration 'is configured' — which implies the license and FortiSandbox configuration have already been validated. If the license were invalid or missing, FortiGate would display a clear license error in the FortiSandbox settings page rather than a general integration failure. Since the problem is described as configuration-level, a licensing issue is not the correct cause.
- ✓
Flow-based inspection does not support FortiSandbox integration; proxy-based inspection is required.
Why this is correct
FortiSandbox file submission is only supported in proxy-based inspection mode on FortiGate models. Flow-based inspection does not buffer complete files for upload; it can only perform hash-based outbreak prevention queries against the FortiSandbox database. Because the file must be fully sent to FortiSandbox for analysis, the antivirus and sandboxing features must be configured with proxy mode in the security policy. Therefore, if the policy uses flow-based inspection, FortiSandbox integration will not perform file submissions.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.