NSE7 Advanced Threat Protection Practice Question
An admin configures Content Disarm and Reconstruction (CDR) on FortiGate to protect against malicious macros in Office documents. After applying the CDR profile to a firewall policy, users complain that documents are not being delivered. What is the most likely cause?
⚠ Common exam trap
Test-takers frequently assume CDR is a simple file-filtering feature that works regardless of inspection mode, but Fortinet explicitly restricts CDR to proxy-based inspection, making flow-based mode a common misconfiguration that causes silent delivery failures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall policy is configured for flow-based inspection
CDR requires proxy-based inspection to intercept, disarm, and reconstruct documents. Flow-based inspection bypasses the deep inspection engine, so CDR cannot process the files, causing delivery failures. FortiGate must use proxy-based inspection mode for CDR to function correctly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The CDR profile has 'File Filter' enabled that blocks the file type
Why it's wrong here
File filter would block before CDR; users would not receive the file at all.
- ✗
The FortiGate is running in transparent mode
Why it's wrong here
Transparent mode supports proxy features including CDR, so not the cause.
- ✓
The firewall policy is configured for flow-based inspection
Why this is correct
CDR requires proxy-based inspection mode. Flow mode does not support CDR, so documents may be dropped.
- ✗
The antivirus profile is not applied to the same policy
Why it's wrong here
CDR can work independently of antivirus; they are separate profiles.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.