Courseiva
Security Profiles →mediumMultiple Choice

NSE4 Security Profiles Practice Question

Which of the following best describes the difference between flow-based and proxy-based inspection for antivirus scanning?

⚠ Common exam trap

A common mix-up: candidates confuse the performance characteristics, mistakenly thinking flow-based is 'less secure' or that proxy-based always requires SSL inspection, when in fact both modes can be applied to different inspection needs and SSL inspection is a separate configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Flow-based inspection uses pattern matching and anomaly detection with low latency, while proxy-based provides full content reassembly and higher detection rates

Flow-based inspection uses pattern matching and anomaly detection to scan traffic with low latency, while proxy-based inspection fully reassembles files and content, enabling deeper analysis and higher detection rates. In Fortinet's FortiOS, flow-based mode is optimized for performance, whereas proxy-based mode provides more thorough inspection by buffering and reconstructing the entire data stream before scanning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Flow-based inspection reassembles the entire file before scanning, while proxy-based scans packets on the fly

    Why it's wrong here

    This is reversed. Flow-based inspection does not reassemble entire files before scanning; it examines packets as they traverse the device using pattern matching and anomaly detection, resulting in low latency. Proxy-based inspection, in contrast, terminates the connection and buffers the full content stream for reassembly before applying detection logic, which is more resource-intensive but enables thorough file-level analysis.

  • ✗

    Flow-based inspection scans first packet and allows, while proxy-based buffers the entire session

    Why it's wrong here

    Flow-based inspection does not simply scan the first packet and allow subsequent traffic. It continuously inspects every packet within a flow, applying signature-based patterns and real-time anomaly detection across the session. While proxy-based does buffer the entire session, the claim that flow-based 'scans first packet and allows' misrepresents its continuous monitoring capability.

  • ✗

    Flow-based inspection requires SSL deep inspection, while proxy-based does not

    Why it's wrong here

    This statement is backwards. SSL deep inspection can be performed by both inspection modes, but it is generally more effective in proxy-based inspection because the device fully decrypts, inspects, and re-encrypts traffic after reassembly. Flow-based inspection may handle SSL without full decryption by analyzing metadata or using heuristics, but it is not 'required' to have SSL deep inspection—neither mode mandates it as their defining characteristic.

  • ✓

    Flow-based inspection uses pattern matching and anomaly detection with low latency, while proxy-based provides full content reassembly and higher detection rates

    Why this is correct

    This correctly captures the core trade-off. Flow-based inspection processes packets in a streaming fashion using pattern matching, protocol anomaly detection, and flow-level heuristics, keeping latency low and throughput high. Proxy-based inspection buffers and reassembles the entire payload, which allows for detecting complex evasions and embedded malware, but at the cost of higher latency and resource usage.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.