NSE4 Security Profiles Practice Question
A FortiGate is configured to integrate with FortiSandbox for advanced threat detection. The antivirus profile is set to send files to FortiSandbox when a virus is detected. What action does FortiGate take on the file while it is being analyzed by FortiSandbox?
⚠ Common exam trap
NSE4 often tests the difference between 'block until verdict' and 'quarantine' actions in antivirus profiles, confusing candidates about whether the file is held or stored.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Blocks the file until a verdict is received from FortiSandbox
When the antivirus profile is configured to send files to FortiSandbox for analysis, FortiGate holds the file in a temporary buffer and does not forward it to the client until a verdict is received. This is known as 'block until verdict' mode. The file is not quarantined on the FortiGate, nor is it immediately blocked or allowed; the session is paused pending the sandbox result.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Quarantines the file on the FortiGate
Why it's wrong here
FortiSandbox integration does not quarantine the file locally on the FortiGate during the analysis period; rather, the FortiGate buffers the file while it sends a copy to FortiSandbox for a verdict. Quarantine is a post-verdict action that occurs only after the sandbox returns a malicious rating, not while the file is still being examined. Therefore, this option describes an action that would happen later, not the file-handling behavior while awaiting the sandbox's decision.
- ✓
Blocks the file until a verdict is received from FortiSandbox
Why this is correct
When the FortiGate is integrated with FortiSandbox, the administrator can configure the sandbox profile to 'block' while the file is being analyzed, meaning the FortiGate holds or buffers the file and does not deliver it to the client until a verdict is received from FortiSandbox. This approach ensures that unknown files are not released to the endpoint unless the sandbox deems them clean, with a fallback action applied if the verdict times out. This is the correct behavior for a blocking integration, as it prevents potential malware from reaching the user during the analysis window.
- ✗
Immediately blocks the file and logs the event
Why it's wrong here
If the FortiGate were to immediately block the file and log the event, it would not send the file to FortiSandbox for analysis in the first place, because the file would already be denied based on local inspection (such as a static signature match) or a pre-defined policy. Immediate blocking without sandboxing is typical for files already known to be malicious, and it defeats the purpose of integrating with FortiSandbox, which is to evaluate unknown files. In a FortiSandbox integration, blocking is normally the outcome of a malicious verdict from the sandbox, not an instant action taken before analysis begins.
- ✗
Allows the file to pass through and logs the event
Why it's wrong here
Allowing the file to pass through and logging the event describes a 'monitor' or 'log-only' mode, where the FortiGate permits the file to reach its destination while FortiSandbox analyzes a copy asynchronously. However, the question's context implies a detection-oriented integration where the FortiGate should not release the file until the verdict is known. If the action were set to 'block,' the FortiGate would not allow the file to pass during analysis, so this option is incorrect for the scenario of waiting for a verdict.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.