NSE4 Security Profiles Practice Question
A FortiGate with antivirus in flow-based inspection mode is not detecting a known virus in HTTP traffic. The same virus is detected when using proxy-based inspection. What is the most likely reason?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Flow-based inspection does not reassemble files or unpack archives, so it misses some viruses
Flow-based inspection processes traffic as a stream without performing full file reassembly or unpacking archives that proxy-based inspection performs. This allows some viruses to evade detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Flow-based inspection does not reassemble files or unpack archives, so it misses some viruses
Why this is correct
In flow-based inspection, FortiOS scans traffic in a single pass by inspecting packets as they traverse the interface without buffering the entire file. Because it does not reassemble the full content or unpack compressed archives (e.g., ZIP, RAR, or base64-encoded files), malware hidden inside these containers can evade detection. Proxy-based inspection, in contrast, buffers the whole object, unpacks archives, and scans each component individually, offering deeper and more thorough virus detection than flow mode.
- ✗
Flow-based inspection requires FortiSandbox integration to detect viruses
Why it's wrong here
Flow-based inspection does not require FortiSandbox integration to detect known viruses; the FortiGate's antivirus engine uses the FortiGuard signature database directly in the data path. FortiSandbox is an optional, complementary service that catches unknown or zero-day malware by executing suspicious files in a sandbox, but it is not a prerequisite for basic signature-based detection. Thus, saying flow-based requires sandbox incorrectly conflates advanced threat detection with standard antivirus capability.
- ✗
The antivirus signature database is outdated for flow-based inspection
Why it's wrong here
The antivirus signature database is maintained globally by FortiGuard and is the same regardless of whether a policy uses flow-based or proxy-based inspection. FortiGate devices receive signature updates through the same FortiGuard update mechanism, so flow mode does not use a separate, older or outdated database. Any signature latency would equally affect both inspection modes and is not a characteristic of flow-based inspection itself.
- ✗
Flow-based inspection only scans on explicit proxy policies
Why it's wrong here
Flow-based inspection is a scanning mode that operates transparently on all firewall policies, whether they are deployed in routed, transparent, or explicit proxy mode. Explicit proxy is just one specific deployment scenario that requires a separate policy type, but flow-based AV scanning works equally well for inline, transparent traffic and SSL inspection. Therefore, restricting flow-based scanning to only explicit proxy policies is incorrect.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.