NSE4 Security Profiles Practice Question
Which inspection mode allows FortiGate to perform virus scanning by reassembling the entire file in memory before scanning, providing better detection but potentially higher latency?
⚠ Common exam trap
NSE4 often tests the confusion between flow-based and proxy-based inspection, where candidates incorrectly assume flow-based mode reassembles the entire file — it does not; only proxy-based inspection buffers the full file in memory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Proxy-based inspection
Proxy-based inspection is the FortiGate mode where the full file is buffered and reassembled in memory before the security profile (AV, IPS, etc.) inspects it. This allows complete-file scanning, so detection of threats that span multiple packets or require the whole file is far better, at the cost of added latency and memory usage. Flow-based inspection, by contrast, scans packets as they stream through, which is faster but can miss threats that only appear once the file is fully assembled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fast-path inspection
Why it's wrong here
FortiGate does not define a 'fast-path' inspection mode for UTM profiles. The term fast-path typically refers to optimized routing or hardware offload, not security scanning. Because antivirus requires the inspection engine to either proxy or stream the content, an unspecified fast-path cannot enable virus scanning.
- ✗
Deep inspection
Why it's wrong here
Deep inspection is a decryption profile that allows FortiOS to inspect SSL/TLS encrypted traffic by re-encrypting it, but it is not an antivirus scanning method. After decryption, the traffic is passed to either flow- or proxy-based inspection for actual virus detection. Therefore, selecting deep inspection alone does not invoke the antivirus scanner; it merely provides visibility into encrypted payloads.
- ✓
Proxy-based inspection
Why this is correct
Proxy-based inspection is the correct mode because it fully reassembles and buffers the entire file in memory before submitting it to the antivirus engine. This complete content capture enables sophisticated pattern matching and detection of threats that rely on whole-file context, at the expense of increased latency. For maximum virus detection assurance, FortiGate administrators use proxy-based inspection for antivirus profiles.
- ✗
Flow-based inspection
Why it's wrong here
Flow-based inspection performs antivirus scanning in real time as packets traverse the firewall, without waiting to reassemble the full file. While this reduces latency and resource consumption, it cannot quarantine or detect viruses that are only identifiable when the complete file is present. It is a valid scanning mode, but it is not the mode that 'allows' virus scanning in the comprehensive, buffered sense the question asks for.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which inspection mode in the antivirus profile processes traffic by buffering the entire file before scanning, allowing more thorough detection but potentially increasing latency?
easy- ✓ A.Proxy-based inspection
- B.Deep inspection
- C.DNS inspection
- D.Flow-based inspection
Why A: Proxy-based inspection in the antivirus profile buffers the entire file in memory before scanning, enabling thorough detection of threats like polymorphic malware or embedded exploits. This mode reassembles the full data stream, allowing the FortiGate to perform deep content analysis, but it introduces higher latency due to the buffering and reassembly process.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.