Courseiva
Security Profiles →mediumMultiple Choice

NSE4 Security Profiles Practice Question

A FortiGate with antivirus in flow-based inspection mode is not detecting a known virus in HTTP traffic. The same virus is detected when using proxy-based inspection. What is the most likely reason?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Flow-based inspection does not reassemble files or unpack archives, so it misses some viruses

Flow-based inspection processes traffic as a stream without performing full file reassembly or unpacking archives that proxy-based inspection performs. This allows some viruses to evade detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Flow-based inspection does not reassemble files or unpack archives, so it misses some viruses

    Why this is correct

    In flow-based inspection, FortiOS scans traffic in a single pass by inspecting packets as they traverse the interface without buffering the entire file. Because it does not reassemble the full content or unpack compressed archives (e.g., ZIP, RAR, or base64-encoded files), malware hidden inside these containers can evade detection. Proxy-based inspection, in contrast, buffers the whole object, unpacks archives, and scans each component individually, offering deeper and more thorough virus detection than flow mode.

  • ✗

    Flow-based inspection requires FortiSandbox integration to detect viruses

    Why it's wrong here

    Flow-based inspection does not require FortiSandbox integration to detect known viruses; the FortiGate's antivirus engine uses the FortiGuard signature database directly in the data path. FortiSandbox is an optional, complementary service that catches unknown or zero-day malware by executing suspicious files in a sandbox, but it is not a prerequisite for basic signature-based detection. Thus, saying flow-based requires sandbox incorrectly conflates advanced threat detection with standard antivirus capability.

  • ✗

    The antivirus signature database is outdated for flow-based inspection

    Why it's wrong here

    The antivirus signature database is maintained globally by FortiGuard and is the same regardless of whether a policy uses flow-based or proxy-based inspection. FortiGate devices receive signature updates through the same FortiGuard update mechanism, so flow mode does not use a separate, older or outdated database. Any signature latency would equally affect both inspection modes and is not a characteristic of flow-based inspection itself.

  • ✗

    Flow-based inspection only scans on explicit proxy policies

    Why it's wrong here

    Flow-based inspection is a scanning mode that operates transparently on all firewall policies, whether they are deployed in routed, transparent, or explicit proxy mode. Explicit proxy is just one specific deployment scenario that requires a separate policy type, but flow-based AV scanning works equally well for inline, transparent traffic and SSL inspection. Therefore, restricting flow-based scanning to only explicit proxy policies is incorrect.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.