Courseiva
Security Profiles →easyMultiple Choice

NSE4 Security Profiles Practice Question

Which two inspection modes are available for antivirus scanning on a FortiGate?

⚠ Common exam trap

Test-takers frequently confuse firewall inspection modes (stateful/stateless) or IDS/IPS deployment modes (inline/passive) with the two antivirus scanning modes, which are specifically flow-based and proxy-based on FortiGate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Flow-based and proxy-based

FortiGate offers two distinct inspection modes for antivirus scanning: flow-based and proxy-based. Flow-based inspection uses a single-pass, low-latency engine that examines traffic as it passes through, while proxy-based inspection buffers and reassembles the entire file before scanning, providing deeper analysis at the cost of higher latency. Both modes are configured within the antivirus security profile to match different performance and security requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Stateful and stateless

    Why it's wrong here

    Stateful and stateless are firewall operation modes that describe whether a device tracks connection state in a session table. Stateful inspection (default on FortiGate) matches packets against existing sessions and applies related security policies; stateless, or packet filter, inspects each packet independently. These do not describe antivirus inspection, which instead uses flow or proxy modes to scan traffic for malware.

  • ✓

    Flow-based and proxy-based

    Why this is correct

    Flow-based and proxy-based are the two security profile inspection modes supported on FortiGate for antivirus and other UTM features. Flow mode performs scanning in a single pass directly on packets transiting the kernel and can be accelerated by FortiASIC content processors (CP), lowering latency and supporting high-throughput links. Proxy mode terminates the TCP session in a dedicated proxy engine, reassembles and buffers the full content before scanning, enabling deeper inspection of files and more granular control at the cost of higher latency and resource consumption.

  • ✗

    Inline and passive

    Why it's wrong here

    Inline and passive are typical deployment modes for intrusion detection/prevention systems, such as Snort/Suricata. Inline means the appliance resides physically in the data path and can drop or reject malicious traffic; passive mode copies traffic off a tap or SPAN port for monitoring without affecting forwarding. FortiGate antivirus inspection is not described in these terms; it is a security profile applied to traffic that is already passing through the FortiGate, not an inline/passive sensor.

  • ✗

    Kernel-based and user-based

    Why it's wrong here

    Kernel-based and user-based are not official inspection modes in FortiGate. While flow inspection works in the kernel forwarding path and proxy inspection runs in user-space daemons, FortiGate names the modes by the inspection engine (flow vs proxy), not by execution context. Using 'kernel-based' or 'user-based' would inaccurately imply only one context handles scanning, whereas FortiGate's flow mode still uses kernel plus CP assistance and proxy mode uses a full TCP proxy process in user space.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.