Courseiva
Advanced Threat ProtectioneasyMultiple ChoiceObjective-mapped

What is Content Disarm and Reconstruction (CDR) in FortiGate?

What is the primary function of Content Disarm and Reconstruction (CDR) in FortiGate's antivirus profile?

Quick Answer

The answer is that Content Disarm and Reconstruction (CDR) in FortiGate’s antivirus profile is primarily used to remove active content and rebuild files to eliminate hidden threats. This is correct because CDR strips potentially dangerous elements—such as macros, scripts, and embedded objects—from incoming documents like PDFs or Office files, then reconstructs a clean, safe version that retains the file’s usability. By doing so, CDR prevents exploits that rely on malicious active content, which often bypass signature-based detection methods. On the Fortinet NSE 7 Advanced Security exam, this concept tests your understanding of proactive threat mitigation within a layered security approach; a common trap is confusing CDR with traditional antivirus scanning, which only detects known signatures rather than disarming unknown threats. Remember the memory tip: “Strip and rebuild, don’t just scan and hope”—CDR breaks the attack chain by removing the weapon before the file ever reaches the user.

⚠ Common exam trap

It's easy for candidates to confuse CDR with traditional antivirus or sandboxing, assuming it detects threats via signatures or behavioral analysis, when in fact it proactively removes all active content regardless of whether a threat is known.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

To remove active content and rebuild files to eliminate hidden threats

Content Disarm and Reconstruction (CDR) works by stripping active content (e.g., macros, scripts, OLE objects) from incoming files and rebuilding them into a safe, sanitized version. This eliminates hidden threats such as embedded exploits or malicious code that signature-based detection might miss, providing protection against zero-day and unknown attacks. Option D correctly identifies this core function of removing active content and rebuilding files to neutralize threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • To detect and block zero-day malware using machine learning

    Why it's wrong here

    That is the role of the machine learning engine, not CDR.

  • To reconstruct files that were corrupted during transmission

    Why it's wrong here

    CDR focuses on security, not data recovery.

  • To compress files for faster scanning

    Why it's wrong here

    CDR does not compress; it disarms and reconstructs.

  • To remove active content and rebuild files to eliminate hidden threats

    Why this is correct

    CDR strips potentially malicious elements and reconstructs a sanitized file.

About these practice questions

This NSE7 question is part of Courseiva's 940-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE7

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. What is the primary purpose of Content Disarm and Reconstruction (CDR) in FortiGate's antivirus features?

easy
  • A.To remove potentially malicious content from documents and rebuild them as safe files
  • B.To convert files into PDF format for safer viewing
  • C.To detect zero-day malware using sandboxing
  • D.To block all files containing macros

Why A: Content Disarm and Reconstruction (CDR) is designed to remove active or potentially malicious content—such as macros, scripts, embedded objects, and OLE links—from documents (e.g., Office files, PDFs) and then reconstruct them as sanitized, safe versions. This approach prevents threats like macro-based malware or exploit-laden attachments from reaching users, even if the file contains previously unknown (zero-day) payloads, by stripping the dangerous components rather than relying solely on signature-based detection.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.