NSE7 Enterprise Firewall and VDOMs Practice Question
A FortiGate admin configures a firewall policy with an antivirus profile in flow-based inspection mode. The admin notices that some large files are being scanned but others are allowed without scanning. What is the most likely cause?
⚠ Common exam trap
Many exam-takers assume flow-based inspection can scan any file size, overlooking the buffer size limitation that causes large files to bypass scanning entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The FortiGate's antivirus buffer size is exceeded, causing some files to bypass scanning
In flow-based inspection, FortiGate uses a buffer to reassemble files before scanning. When a file exceeds the configured antivirus buffer size (default 1 MB for flow-based), the FortiGate cannot buffer the entire file for scanning and allows it to pass without inspection. This explains why some large files bypass scanning while smaller ones are scanned.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The antivirus signatures are outdated
Why it's wrong here
Outdated signatures cause missed detections across all file sizes, not selective scanning of some large files while others pass unscanned. It is tempting because signature currency is a genuine antivirus concern, and updating them would be correct when known malware is consistently evading detection regardless of file size.
- ✗
The antivirus profile has an exemption for certain file types
Why it's wrong here
File-type exemptions skip scanning by design, but they apply consistently to every file of that type, not selectively to some large files while others are scanned. It is tempting because exemptions genuinely bypass inspection, and configuring them would be correct when specific trusted formats must avoid scanning overhead.
- ✓
The FortiGate's antivirus buffer size is exceeded, causing some files to bypass scanning
Why this is correct
In flow-based antivirus inspection, files are buffered up to a configured limit before scanning. Files exceeding that buffer size cannot be held for inspection, so the FortiGate passes them unscanned, explaining why only some large files bypass scanning.
- ✗
Flow-based inspection cannot scan files larger than 10 MB
Why it's wrong here
Flow-based inspection scans files of any size up to the configured oversize limit, which defaults to 10 MB but is adjustable; the fixed 10 MB ceiling does not exist. It is tempting because the default oversize threshold is 10 MB, and raising that limit would be correct when files exceed the configured maximum.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.