Courseiva
Advanced Threat ProtectionmediumMultiple ChoiceObjective-mapped

NSE7 Advanced Threat Protection Practice Question

An administrator configures a FortiGate to integrate with FortiSandbox for inline scanning. The policy has an antivirus profile with FortiSandbox enabled. What condition must be met for files to be submitted to FortiSandbox?

⚠ Common exam trap

Test-takers frequently assume flow-based inspection is sufficient for inline sandboxing, but FortiGate explicitly requires proxy-based inspection to buffer and submit files for verdict-based blocking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The antivirus profile must use proxy-based inspection mode

For files to be submitted to FortiSandbox during inline scanning, the antivirus profile must use proxy-based inspection mode. This is because proxy-based inspection allows the FortiGate to buffer the entire file, perform deep analysis, and then forward it to FortiSandbox for verdict-based blocking. Flow-based inspection, in contrast, streams packets and cannot hold files for submission, making proxy mode a prerequisite for inline FortiSandbox integration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The antivirus profile must use proxy-based inspection mode

    Why this is correct

    Proxy-based inspection is required for inline FortiSandbox file submission.

  • The FortiSandbox must be on the same subnet as the FortiGate

    Why it's wrong here

    FortiSandbox can be reachable via routed networks.

  • The FortiGate must be in NAT mode

    Why it's wrong here

    NAT mode is irrelevant; FortiSandbox works in both NAT and transparent modes.

  • SSL inspection must be disabled

    Why it's wrong here

    SSL inspection does not prevent FortiSandbox submission.

About these practice questions

Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.