Courseiva
Security Profiles →mediumMultiple Choice

NSE4 Security Profiles Practice Question

An organization uses FortiSandbox to analyze suspicious files. The FortiGate is configured to send files to FortiSandbox for analysis when the antivirus scan fails to reach a verdict. Which antivirus inspection mode must be used on the firewall policy for this integration to work?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Proxy-based inspection

Proxy-based inspection buffers the file and can hold the connection until FortiSandbox returns a verdict. Flow-based does not support this hold-and-wait mechanism.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Both flow and proxy modes support FortiSandbox equally

    Why it's wrong here

    Although flow-based and proxy-based inspection modes can both be integrated with FortiSandbox, they are not functionally equal. Proxy-based inspection buffers the entire file and holds the connection until FortiSandbox returns a verdict, enabling true blocking of malicious files. In contrast, flow-based inspection forwards only a file hash or a copy to FortiSandbox without holding the connection, so it cannot quarantine the file at the moment of detection. Therefore, saying both support FortiSandbox 'equally' ignores the significant difference in enforcement capability.

  • ✗

    Deep inspection

    Why it's wrong here

    Deep inspection refers to SSL/TLS decryption, not an antivirus inspection mode. It is a profile that allows FortiGate to decrypt HTTPS traffic so that security profiles, including antivirus, can inspect the content. While deep inspection can be used alongside FortiSandbox for encrypted traffic, it is not the mode that sends files to FortiSandbox. Without an antivirus profile configured with FortiSandbox, deep inspection alone does not submit files for sandbox analysis.

  • ✓

    Proxy-based inspection

    Why this is correct

    Proxy-based inspection is the correct mode because it fully buffers the file, forwards it to FortiSandbox, and pauses the session until a verdict is returned. This allows FortiGate to block the file before it reaches the client if FortiSandbox determines it is malicious. The connection-holding behavior is essential for quarantine and real-time enforcement. In contrast, flow-based inspection lacks this holding capability and therefore cannot provide the same level of blocking.

  • ✗

    Flow-based inspection

    Why it's wrong here

    Flow-based inspection can indeed send files to FortiSandbox, but only in a 'copy-and-continue' manner. The FortiGate forwards the file or a hash to FortiSandbox and immediately allows the traffic to proceed without waiting for a verdict. This means it acts as a monitoring or detection tool rather than a blocking control. Even when configured correctly, flow-based mode does not hold the connection, so malicious files may reach the user before the sandbox analysis completes.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.