NSE4 Security Profiles Practice Question
Which two inspection modes are available for antivirus scanning on a FortiGate?
⚠ Common exam trap
Test-takers frequently confuse firewall inspection modes (stateful/stateless) or IDS/IPS deployment modes (inline/passive) with the two antivirus scanning modes, which are specifically flow-based and proxy-based on FortiGate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Flow-based and proxy-based
FortiGate offers two distinct inspection modes for antivirus scanning: flow-based and proxy-based. Flow-based inspection uses a single-pass, low-latency engine that examines traffic as it passes through, while proxy-based inspection buffers and reassembles the entire file before scanning, providing deeper analysis at the cost of higher latency. Both modes are configured within the antivirus security profile to match different performance and security requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Stateful and stateless
Why it's wrong here
Stateful and stateless are firewall operation modes that describe whether a device tracks connection state in a session table. Stateful inspection (default on FortiGate) matches packets against existing sessions and applies related security policies; stateless, or packet filter, inspects each packet independently. These do not describe antivirus inspection, which instead uses flow or proxy modes to scan traffic for malware.
- ✓
Flow-based and proxy-based
Why this is correct
Flow-based and proxy-based are the two security profile inspection modes supported on FortiGate for antivirus and other UTM features. Flow mode performs scanning in a single pass directly on packets transiting the kernel and can be accelerated by FortiASIC content processors (CP), lowering latency and supporting high-throughput links. Proxy mode terminates the TCP session in a dedicated proxy engine, reassembles and buffers the full content before scanning, enabling deeper inspection of files and more granular control at the cost of higher latency and resource consumption.
- ✗
Inline and passive
Why it's wrong here
Inline and passive are typical deployment modes for intrusion detection/prevention systems, such as Snort/Suricata. Inline means the appliance resides physically in the data path and can drop or reject malicious traffic; passive mode copies traffic off a tap or SPAN port for monitoring without affecting forwarding. FortiGate antivirus inspection is not described in these terms; it is a security profile applied to traffic that is already passing through the FortiGate, not an inline/passive sensor.
- ✗
Kernel-based and user-based
Why it's wrong here
Kernel-based and user-based are not official inspection modes in FortiGate. While flow inspection works in the kernel forwarding path and proxy inspection runs in user-space daemons, FortiGate names the modes by the inspection engine (flow vs proxy), not by execution context. Using 'kernel-based' or 'user-based' would inaccurately imply only one context handles scanning, whereas FortiGate's flow mode still uses kernel plus CP assistance and proxy mode uses a full TCP proxy process in user space.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.