NSE4 Security Profiles Practice Question
A FortiGate receives a file via SMTP that contains a virus. The antivirus profile is set to 'Block' for viruses and the action is set to 'Quarantine'. However, the email is delivered to the user with the infected attachment. What could be the reason?
⚠ Common exam trap
Test-takers frequently assume the 'Block' and 'Quarantine' actions apply globally to all traffic, overlooking that flow-based inspection requires explicit protocol selection within the antivirus profile for SMTP scanning to occur.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The antivirus profile is using flow-based inspection and the SMTP scan is not enabled
B is correct because when an antivirus profile uses flow-based inspection, it must have SMTP scanning explicitly enabled in the profile settings. If SMTP scan is not enabled, the FortiGate will not inspect SMTP traffic for viruses, allowing infected attachments to pass through regardless of the antivirus action set to 'Block' and 'Quarantine'. Proxy-based inspection, by contrast, scans all protocols by default, but flow-based requires per-protocol enablement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The email filter profile is overriding the antivirus action
Why it's wrong here
In FortiGate, UTM profiles such as email filter and antivirus are evaluated independently within the same security policy. An email filter profile can inspect SMTP metadata and enforce actions like discard or tag, but it never overrides or modifies the antivirus engine's own verdict on an attachment. A virus detection always triggers the action specified in the antivirus profile (block, quarantine, or pass-with-notification), regardless of email filter settings, so a delivered file cannot be attributed to the email filter overriding AV.
- ✓
The antivirus profile is using flow-based inspection and the SMTP scan is not enabled
Why this is correct
Flow-based antivirus inspection does not scan every protocol by default; the antivirus profile must explicitly enable each protocol such as SMTP. In a flow-based profile, if SMTP scanning is left unchecked, mail attachments bypass the antivirus engine entirely — even when signatures are current and the same virus would be caught over HTTP or FTP. Proxy-based inspection, by contrast, scans all supported protocols (SMTP, POP3, IMAP, HTTP, FTP) out of the box, which is why this behavior is specifically tied to a flow-based profile with SMTP disabled.
- ✗
The antivirus signatures are outdated
Why it's wrong here
If antivirus signatures were outdated, the FortiGate would lack the pattern for the virus and would not identify it at all — the file would be forwarded with no AV log event. The question's scenario is about a known virus that is detected but not blocked; outdated signatures cannot produce a detection result. Signature updates are also global, not profile-specific, so they affect all protocols equally and would not selectively miss SMTP while catching the same file elsewhere.
- ✗
The file is larger than the FortiGate's virus database can handle
Why it's wrong here
FortiGate's antivirus engine applies a configurable 'maximum file size to scan' limit; files larger than that limit are typically allowed to pass with an 'oversized' log entry and no viral verdict. If the scanner actually detected the virus, the file was within the scan-size threshold, so a size limitation cannot explain why detection failed to block delivery. Moreover, the 'virus database' is a signature repository, not a storage area for file content, and its size does not impose any per-message limit.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.