NSE4 Security Profiles Practice Question
An organization uses FortiSandbox to detect advanced threats. The administrator wants to ensure that files downloaded from the internet are sent to FortiSandbox for analysis before being delivered to users. Which Antivirus profile setting should be configured?
⚠ Common exam trap
Candidates often confuse 'Inline Scan' with 'FortiSandbox Monitoring' or 'Quarantine', thinking any FortiSandbox-related option will send files before delivery, but only 'Inline Scan' enforces the synchronous hold-and-scan behavior required by the question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable 'Inline Scan' for FortiSandbox
To ensure files downloaded from the internet are sent to FortiSandbox for analysis before delivery to users, the 'Inline Scan' option for FortiSandbox must be enabled in the Antivirus profile. This setting causes the FortiGate to hold the file, send it to FortiSandbox, and only deliver it to the user after receiving a verdict (e.g., clean or malicious). Without inline scanning, files are delivered first and scanned asynchronously, which defeats the 'before delivery' requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable 'Inline Scan' for FortiSandbox
Why this is correct
Inline Scan mode on FortiGate's FortiSandbox integration causes the firewall to submit a file to the sandbox and temporarily buffer the client's request until a verdict is returned. Only a 'clean' verdict releases the file to the end user; malicious or suspicious files are blocked and quarantined. This is the only mode that guarantees the file is not delivered before analysis completes, making it essential for preventing zero-day infections in real time.
- ✗
Enable 'FortiSandbox Monitoring'
Why it's wrong here
FortiSandbox Monitoring mode, sometimes called 'Forward' or 'Copy', sends a duplicate of the file to FortiSandbox for analysis without interrupting the original data stream. The end user receives the file immediately, and FortiGate later logs or optionally quarantines the file if FortiSandbox reports it malicious. Because delivery is not suspended, monitoring cannot block an initial zero-day attack — it only enables 'detection after the fact' and is best for low-latency networks that accept residual risk.
- ✗
Enable 'FortiSandbox Quarantine'
Why it's wrong here
Enabling 'FortiSandbox Quarantine' does not configure how files are submitted for analysis; rather, it defines the action FortiGate takes on files that FortiSandbox has already determined to be malicious, such as moving them to a quarantine area. Files first need to be scanned by FortiSandbox through inline or monitoring mode, and only then can quarantine trigger on a malicious verdict. Selecting this option alone leaves the FortiGate without any active sandbox submission, so it cannot delay traffic while waiting for an unknown file's verdict.
- ✗
Set 'Scan Mode' to 'Quick'
Why it's wrong here
The 'Scan Mode' parameter, with options like 'Quick' and 'Full', controls the depth of FortiGate's own local antivirus inspection — for instance, Quick mode may skip archive extraction or content emulation. It has no effect on whether or how files are sent to FortiSandbox; even in Quick mode, a file can still be forwarded to the sandbox if the right scan mode (inline or monitor) is also configured. Relying on Quick Scan alone will not provide the required pre-delivery blocking because the file either gets delivered after local scan or, if sandbox is not enabled, never reaches FortiSandbox at all.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.