Courseiva
Security Profiles →mediumMultiple Choice

NSE4 Security Profiles Practice Question

A FortiGate is configured to integrate with FortiSandbox for advanced threat detection. The antivirus profile is set to send files to FortiSandbox when a virus is detected. What action does FortiGate take on the file while it is being analyzed by FortiSandbox?

⚠ Common exam trap

NSE4 often tests the difference between 'block until verdict' and 'quarantine' actions in antivirus profiles, confusing candidates about whether the file is held or stored.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Blocks the file until a verdict is received from FortiSandbox

When the antivirus profile is configured to send files to FortiSandbox for analysis, FortiGate holds the file in a temporary buffer and does not forward it to the client until a verdict is received. This is known as 'block until verdict' mode. The file is not quarantined on the FortiGate, nor is it immediately blocked or allowed; the session is paused pending the sandbox result.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Quarantines the file on the FortiGate

    Why it's wrong here

    FortiSandbox integration does not quarantine the file locally on the FortiGate during the analysis period; rather, the FortiGate buffers the file while it sends a copy to FortiSandbox for a verdict. Quarantine is a post-verdict action that occurs only after the sandbox returns a malicious rating, not while the file is still being examined. Therefore, this option describes an action that would happen later, not the file-handling behavior while awaiting the sandbox's decision.

  • ✓

    Blocks the file until a verdict is received from FortiSandbox

    Why this is correct

    When the FortiGate is integrated with FortiSandbox, the administrator can configure the sandbox profile to 'block' while the file is being analyzed, meaning the FortiGate holds or buffers the file and does not deliver it to the client until a verdict is received from FortiSandbox. This approach ensures that unknown files are not released to the endpoint unless the sandbox deems them clean, with a fallback action applied if the verdict times out. This is the correct behavior for a blocking integration, as it prevents potential malware from reaching the user during the analysis window.

  • ✗

    Immediately blocks the file and logs the event

    Why it's wrong here

    If the FortiGate were to immediately block the file and log the event, it would not send the file to FortiSandbox for analysis in the first place, because the file would already be denied based on local inspection (such as a static signature match) or a pre-defined policy. Immediate blocking without sandboxing is typical for files already known to be malicious, and it defeats the purpose of integrating with FortiSandbox, which is to evaluate unknown files. In a FortiSandbox integration, blocking is normally the outcome of a malicious verdict from the sandbox, not an instant action taken before analysis begins.

  • ✗

    Allows the file to pass through and logs the event

    Why it's wrong here

    Allowing the file to pass through and logging the event describes a 'monitor' or 'log-only' mode, where the FortiGate permits the file to reach its destination while FortiSandbox analyzes a copy asynchronously. However, the question's context implies a detection-oriented integration where the FortiGate should not release the file until the verdict is known. If the action were set to 'block,' the FortiGate would not allow the file to pass during analysis, so this option is incorrect for the scenario of waiting for a verdict.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.