Fortinet FortiOS 7.6 NSE4_FGT_AD-7.6 Antivirus Scanning Protocol Options Events Practice Test
This Fortinet NSE4_FGT_AD-7.6 practice test focuses on antivirus scanning protocol options events and troubleshooting through original applied scenarios aligned to the current Fortinet NSE 4 – FortiOS 7.6 Administrator scope for FortiOS 7.6.0. Use the full ExamSnap NSE4_FGT_AD-7.6 collection for broader practice across all current domains. For broader exam preparation, review the Fortinet NSE4_FGT_AD-7.6 Exam Dumps page.
Question 1
An incident at Adventure Works requires the security engineer to scan supported clear-text file transfers for known malware. What should be done first? The choice should follow normal FortiOS administration practice.
- Maintain FortiGuard antivirus entitlement and signature updates and verify update status
- Review and apply the correct protocol-options profile and port handling for the policy
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
- Review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
Correct answer: E
Explanation
- Current AV databases are required to identify newly added malware signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan supported clear-text file transfers for known malware.
- Protocol options define how FortiGate identifies and processes supported application protocols for inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan supported clear-text file transfers for known malware.
- Antivirus cannot inspect an encrypted payload it never decrypts. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan supported clear-text file transfers for known malware.
- AV logs record detections and the action FortiGate took on the object. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan supported clear-text file transfers for known malware.
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior. Antivirus scanning is performed by a security profile on traffic allowed through the policy.
Question 2
For a FortiGate 7.6 deployment at Fourth Coffee, which option correctly addresses the need to scan malware inside HTTPS downloads? The solution must preserve the existing production design where possible.
- Use full SSL inspection together with the antivirus profile on the matching policy
- Review protocol and antivirus oversize or size-limit behavior and tune the limit only after considering resource and security impact
- Review and apply the correct protocol-options profile and port handling for the policy
- Confirm the detection and use the narrowest appropriate exemption or signature handling change
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
Correct answer: A
Explanation
- The encrypted payload must be decrypted before antivirus can inspect the downloaded content. This directly satisfies the stated requirement.
- Inspection limits can change how oversized objects are handled. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan malware inside HTTPS downloads.
- Protocol options define how FortiGate identifies and processes supported application protocols for inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan malware inside HTTPS downloads.
- Targeted remediation preserves the rest of the antivirus protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan malware inside HTTPS downloads.
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan malware inside HTTPS downloads.
Learning point: For this FortiOS 7.6 scenario, use full SSL inspection together with the antivirus profile on the matching policy. The encrypted payload must be decrypted before antivirus can inspect the downloaded content.
Question 3
Consolidated Messenger has validated routing and basic reachability. The remaining requirement is to ensure antivirus inspects the expected application protocols and nonstandard ports as designed. Which action should the team take? The change is being made during a controlled production window.
- Review protocol and antivirus oversize or size-limit behavior and tune the limit only after considering resource and security impact
- Review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
- Review and apply the correct protocol-options profile and port handling for the policy
- Maintain FortiGuard antivirus entitlement and signature updates and verify update status
Correct answer: D
Explanation
- Inspection limits can change how oversized objects are handled. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure antivirus inspects the expected application protocols and nonstandard ports as designed.
- AV logs record detections and the action FortiGate took on the object. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure antivirus inspects the expected application protocols and nonstandard ports as designed.
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure antivirus inspects the expected application protocols and nonstandard ports as designed.
- Protocol options define how FortiGate identifies and processes supported application protocols for inspection. This directly satisfies the stated requirement.
- Current AV databases are required to identify newly added malware signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure antivirus inspects the expected application protocols and nonstandard ports as designed.
Learning point: For this FortiOS 7.6 scenario, review and apply the correct protocol-options profile and port handling for the policy. Protocol options define how FortiGate identifies and processes supported application protocols for inspection.
Question 4
At VanArsdel, a infrastructure engineer is handling a FortiGate 7.6 change. The requirement is to troubleshoot file scanning that stops because the object exceeds configured inspection limits. What should the administrator do? The team will validate the result immediately after the change.
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
- Review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context
- Confirm the detection and use the narrowest appropriate exemption or signature handling change
- Review protocol and antivirus oversize or size-limit behavior and tune the limit only after considering resource and security impact
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
Correct answer: D
Explanation
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot file scanning that stops because the object exceeds configured inspection limits.
- AV logs record detections and the action FortiGate took on the object. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot file scanning that stops because the object exceeds configured inspection limits.
- Targeted remediation preserves the rest of the antivirus protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot file scanning that stops because the object exceeds configured inspection limits.
- Inspection limits can change how oversized objects are handled. This directly satisfies the stated requirement.
- Antivirus cannot inspect an encrypted payload it never decrypts. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot file scanning that stops because the object exceeds configured inspection limits.
Learning point: For this FortiOS 7.6 scenario, review protocol and antivirus oversize or size-limit behavior and tune the limit only after considering resource and security impact. Inspection limits can change how oversized objects are handled.
Question 5
During a maintenance window at Northwind Health, the team must confirm whether FortiGate blocked a file because of an antivirus signature. Which action is the most appropriate? No unrelated security controls should be changed.
- Maintain FortiGuard antivirus entitlement and signature updates and verify update status
- Review protocol and antivirus oversize or size-limit behavior and tune the limit only after considering resource and security impact
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
- Review and apply the correct protocol-options profile and port handling for the policy
- Review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context
Correct answer: E
Explanation
- Current AV databases are required to identify newly added malware signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to confirm whether FortiGate blocked a file because of an antivirus signature.
- Inspection limits can change how oversized objects are handled. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to confirm whether FortiGate blocked a file because of an antivirus signature.
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to confirm whether FortiGate blocked a file because of an antivirus signature.
- Protocol options define how FortiGate identifies and processes supported application protocols for inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to confirm whether FortiGate blocked a file because of an antivirus signature.
- AV logs record detections and the action FortiGate took on the object. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context. AV logs record detections and the action FortiGate took on the object.
Question 6
A change review at Blue Yonder Airlines identifies one requirement: keep malware detection current. Which FortiGate action best satisfies it? The administrator wants a configuration that is easy to audit later.
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
- Use full SSL inspection together with the antivirus profile on the matching policy
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
- Confirm the detection and use the narrowest appropriate exemption or signature handling change
- Maintain FortiGuard antivirus entitlement and signature updates and verify update status
Correct answer: E
Explanation
- Antivirus cannot inspect an encrypted payload it never decrypts. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to keep malware detection current.
- The encrypted payload must be decrypted before antivirus can inspect the downloaded content. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to keep malware detection current.
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to keep malware detection current.
- Targeted remediation preserves the rest of the antivirus protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to keep malware detection current.
- Current AV databases are required to identify newly added malware signatures. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, maintain FortiGuard antivirus entitlement and signature updates and verify update status. Current AV databases are required to identify newly added malware signatures.
Question 7
While troubleshooting at Trey Research, the security engineer needs to troubleshoot malware that passes through only when the traffic is encrypted. What is the best next step? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.
- Review protocol and antivirus oversize or size-limit behavior and tune the limit only after considering resource and security impact
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
- Confirm the detection and use the narrowest appropriate exemption or signature handling change
- Review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
Correct answer: E
Explanation
- Inspection limits can change how oversized objects are handled. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot malware that passes through only when the traffic is encrypted.
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot malware that passes through only when the traffic is encrypted.
- Targeted remediation preserves the rest of the antivirus protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot malware that passes through only when the traffic is encrypted.
- AV logs record detections and the action FortiGate took on the object. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot malware that passes through only when the traffic is encrypted.
- Antivirus cannot inspect an encrypted payload it never decrypts. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, verify full SSL inspection is active and working for the session before changing antivirus signatures. Antivirus cannot inspect an encrypted payload it never decrypts.
Question 8
Nod Publishers is standardizing its FortiGate 7.6 operations. Which approach should it use to avoid disabling all antivirus after one false positive? The team wants the smallest change that directly addresses the requirement.
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
- Maintain FortiGuard antivirus entitlement and signature updates and verify update status
- Confirm the detection and use the narrowest appropriate exemption or signature handling change
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
- Review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context
Correct answer: C
Explanation
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid disabling all antivirus after one false positive.
- Current AV databases are required to identify newly added malware signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid disabling all antivirus after one false positive.
- Targeted remediation preserves the rest of the antivirus protection. This directly satisfies the stated requirement.
- Antivirus cannot inspect an encrypted payload it never decrypts. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid disabling all antivirus after one false positive.
- AV logs record detections and the action FortiGate took on the object. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid disabling all antivirus after one false positive.
Learning point: For this FortiOS 7.6 scenario, confirm the detection and use the narrowest appropriate exemption or signature handling change. Targeted remediation preserves the rest of the antivirus protection.
Question 9
A production ticket for Contoso Finance states that administrators must scan supported clear-text file transfers for known malware. Which choice is correct? The choice should follow normal FortiOS administration practice.
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
- Use full SSL inspection together with the antivirus profile on the matching policy
- Review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context
- Confirm the detection and use the narrowest appropriate exemption or signature handling change
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
Correct answer: E
Explanation
- Antivirus cannot inspect an encrypted payload it never decrypts. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan supported clear-text file transfers for known malware.
- The encrypted payload must be decrypted before antivirus can inspect the downloaded content. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan supported clear-text file transfers for known malware.
- AV logs record detections and the action FortiGate took on the object. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan supported clear-text file transfers for known malware.
- Targeted remediation preserves the rest of the antivirus protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan supported clear-text file transfers for known malware.
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior. Antivirus scanning is performed by a security profile on traffic allowed through the policy.
Question 10
The security team at Litware Logistics wants to scan malware inside HTTPS downloads. Which FortiGate configuration or action most directly meets that goal? The solution must preserve the existing production design where possible.
- Confirm the detection and use the narrowest appropriate exemption or signature handling change
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
- Use full SSL inspection together with the antivirus profile on the matching policy
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
- Review and apply the correct protocol-options profile and port handling for the policy
Correct answer: C
Explanation
- Targeted remediation preserves the rest of the antivirus protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan malware inside HTTPS downloads.
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan malware inside HTTPS downloads.
- The encrypted payload must be decrypted before antivirus can inspect the downloaded content. This directly satisfies the stated requirement.
- Antivirus cannot inspect an encrypted payload it never decrypts. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan malware inside HTTPS downloads.
- Protocol options define how FortiGate identifies and processes supported application protocols for inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan malware inside HTTPS downloads.
Learning point: For this FortiOS 7.6 scenario, use full SSL inspection together with the antivirus profile on the matching policy. The encrypted payload must be decrypted before antivirus can inspect the downloaded content.
Question 11
An incident at Wide World Importers requires the security engineer to ensure antivirus inspects the expected application protocols and nonstandard ports as designed. What should be done first? The change is being made during a controlled production window.
- Review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context
- Maintain FortiGuard antivirus entitlement and signature updates and verify update status
- Use full SSL inspection together with the antivirus profile on the matching policy
- Review and apply the correct protocol-options profile and port handling for the policy
- Confirm the detection and use the narrowest appropriate exemption or signature handling change
Correct answer: D
Explanation
- AV logs record detections and the action FortiGate took on the object. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure antivirus inspects the expected application protocols and nonstandard ports as designed.
- Current AV databases are required to identify newly added malware signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure antivirus inspects the expected application protocols and nonstandard ports as designed.
- The encrypted payload must be decrypted before antivirus can inspect the downloaded content. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure antivirus inspects the expected application protocols and nonstandard ports as designed.
- Protocol options define how FortiGate identifies and processes supported application protocols for inspection. This directly satisfies the stated requirement.
- Targeted remediation preserves the rest of the antivirus protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure antivirus inspects the expected application protocols and nonstandard ports as designed.
Learning point: For this FortiOS 7.6 scenario, review and apply the correct protocol-options profile and port handling for the policy. Protocol options define how FortiGate identifies and processes supported application protocols for inspection.
Question 12
For a FortiGate 7.6 deployment at Graphic Design Institute, which option correctly addresses the need to troubleshoot file scanning that stops because the object exceeds configured inspection limits? The team will validate the result immediately after the change.
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
- Review protocol and antivirus oversize or size-limit behavior and tune the limit only after considering resource and security impact
- Review and apply the correct protocol-options profile and port handling for the policy
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
- Review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context
Correct answer: B
Explanation
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot file scanning that stops because the object exceeds configured inspection limits.
- Inspection limits can change how oversized objects are handled. This directly satisfies the stated requirement.
- Protocol options define how FortiGate identifies and processes supported application protocols for inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot file scanning that stops because the object exceeds configured inspection limits.
- Antivirus cannot inspect an encrypted payload it never decrypts. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot file scanning that stops because the object exceeds configured inspection limits.
- AV logs record detections and the action FortiGate took on the object. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot file scanning that stops because the object exceeds configured inspection limits.
Learning point: For this FortiOS 7.6 scenario, review protocol and antivirus oversize or size-limit behavior and tune the limit only after considering resource and security impact. Inspection limits can change how oversized objects are handled.
Question 13
Lamna Healthcare has validated routing and basic reachability. The remaining requirement is to confirm whether FortiGate blocked a file because of an antivirus signature. Which action should the team take? No unrelated security controls should be changed.
- Review and apply the correct protocol-options profile and port handling for the policy
- Confirm the detection and use the narrowest appropriate exemption or signature handling change
- Review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
Correct answer: C
Explanation
- Protocol options define how FortiGate identifies and processes supported application protocols for inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to confirm whether FortiGate blocked a file because of an antivirus signature.
- Targeted remediation preserves the rest of the antivirus protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to confirm whether FortiGate blocked a file because of an antivirus signature.
- AV logs record detections and the action FortiGate took on the object. This directly satisfies the stated requirement.
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to confirm whether FortiGate blocked a file because of an antivirus signature.
- Antivirus cannot inspect an encrypted payload it never decrypts. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to confirm whether FortiGate blocked a file because of an antivirus signature.
Learning point: For this FortiOS 7.6 scenario, review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context. AV logs record detections and the action FortiGate took on the object.
Question 14
At Tailspin Toys, a infrastructure engineer is handling a FortiGate 7.6 change. The requirement is to keep malware detection current. What should the administrator do? The administrator wants a configuration that is easy to audit later.
- Confirm the detection and use the narrowest appropriate exemption or signature handling change
- Review protocol and antivirus oversize or size-limit behavior and tune the limit only after considering resource and security impact
- Review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context
- Maintain FortiGuard antivirus entitlement and signature updates and verify update status
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
Correct answer: D
Explanation
- Targeted remediation preserves the rest of the antivirus protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to keep malware detection current.
- Inspection limits can change how oversized objects are handled. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to keep malware detection current.
- AV logs record detections and the action FortiGate took on the object. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to keep malware detection current.
- Current AV databases are required to identify newly added malware signatures. This directly satisfies the stated requirement.
- Antivirus cannot inspect an encrypted payload it never decrypts. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to keep malware detection current.
Learning point: For this FortiOS 7.6 scenario, maintain FortiGuard antivirus entitlement and signature updates and verify update status. Current AV databases are required to identify newly added malware signatures.
Question 15
During a maintenance window at Humongous Insurance, the team must troubleshoot malware that passes through only when the traffic is encrypted. Which action is the most appropriate? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.
- Confirm the detection and use the narrowest appropriate exemption or signature handling change
- Maintain FortiGuard antivirus entitlement and signature updates and verify update status
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
- Use full SSL inspection together with the antivirus profile on the matching policy
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
Correct answer: C
Explanation
- Targeted remediation preserves the rest of the antivirus protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot malware that passes through only when the traffic is encrypted.
- Current AV databases are required to identify newly added malware signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot malware that passes through only when the traffic is encrypted.
- Antivirus cannot inspect an encrypted payload it never decrypts. This directly satisfies the stated requirement.
- The encrypted payload must be decrypted before antivirus can inspect the downloaded content. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot malware that passes through only when the traffic is encrypted.
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot malware that passes through only when the traffic is encrypted.
Learning point: For this FortiOS 7.6 scenario, verify full SSL inspection is active and working for the session before changing antivirus signatures. Antivirus cannot inspect an encrypted payload it never decrypts.
Question 16
A change review at Coho Winery identifies one requirement: avoid disabling all antivirus after one false positive. Which FortiGate action best satisfies it? The team wants the smallest change that directly addresses the requirement.
- Confirm the detection and use the narrowest appropriate exemption or signature handling change
- Review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context
- Review protocol and antivirus oversize or size-limit behavior and tune the limit only after considering resource and security impact
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
- Use full SSL inspection together with the antivirus profile on the matching policy
Correct answer: A
Explanation
- Targeted remediation preserves the rest of the antivirus protection. This directly satisfies the stated requirement.
- AV logs record detections and the action FortiGate took on the object. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid disabling all antivirus after one false positive.
- Inspection limits can change how oversized objects are handled. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid disabling all antivirus after one false positive.
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid disabling all antivirus after one false positive.
- The encrypted payload must be decrypted before antivirus can inspect the downloaded content. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid disabling all antivirus after one false positive.
Learning point: For this FortiOS 7.6 scenario, confirm the detection and use the narrowest appropriate exemption or signature handling change. Targeted remediation preserves the rest of the antivirus protection.
Question 17
While troubleshooting at Relecloud, the security engineer needs to scan supported clear-text file transfers for known malware. What is the best next step? The choice should follow normal FortiOS administration practice.
- Confirm the detection and use the narrowest appropriate exemption or signature handling change
- Maintain FortiGuard antivirus entitlement and signature updates and verify update status
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
- Use full SSL inspection together with the antivirus profile on the matching policy
- Review and apply the correct protocol-options profile and port handling for the policy
Correct answer: C
Explanation
- Targeted remediation preserves the rest of the antivirus protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan supported clear-text file transfers for known malware.
- Current AV databases are required to identify newly added malware signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan supported clear-text file transfers for known malware.
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This directly satisfies the stated requirement.
- The encrypted payload must be decrypted before antivirus can inspect the downloaded content. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan supported clear-text file transfers for known malware.
- Protocol options define how FortiGate identifies and processes supported application protocols for inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan supported clear-text file transfers for known malware.
Learning point: For this FortiOS 7.6 scenario, apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior. Antivirus scanning is performed by a security profile on traffic allowed through the policy.
Question 18
Woodgrove Bank is standardizing its FortiGate 7.6 operations. Which approach should it use to scan malware inside HTTPS downloads? The solution must preserve the existing production design where possible.
- Use full SSL inspection together with the antivirus profile on the matching policy
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
- Review protocol and antivirus oversize or size-limit behavior and tune the limit only after considering resource and security impact
- Maintain FortiGuard antivirus entitlement and signature updates and verify update status
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
Correct answer: A
Explanation
- The encrypted payload must be decrypted before antivirus can inspect the downloaded content. This directly satisfies the stated requirement.
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan malware inside HTTPS downloads.
- Inspection limits can change how oversized objects are handled. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan malware inside HTTPS downloads.
- Current AV databases are required to identify newly added malware signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan malware inside HTTPS downloads.
- Antivirus cannot inspect an encrypted payload it never decrypts. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan malware inside HTTPS downloads.
Learning point: For this FortiOS 7.6 scenario, use full SSL inspection together with the antivirus profile on the matching policy. The encrypted payload must be decrypted before antivirus can inspect the downloaded content.
Question 19
A production ticket for Alpine Ski House states that administrators must ensure antivirus inspects the expected application protocols and nonstandard ports as designed. Which choice is correct? The change is being made during a controlled production window.
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
- Review protocol and antivirus oversize or size-limit behavior and tune the limit only after considering resource and security impact
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
- Maintain FortiGuard antivirus entitlement and signature updates and verify update status
- Review and apply the correct protocol-options profile and port handling for the policy
Correct answer: E
Explanation
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure antivirus inspects the expected application protocols and nonstandard ports as designed.
- Inspection limits can change how oversized objects are handled. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure antivirus inspects the expected application protocols and nonstandard ports as designed.
- Antivirus cannot inspect an encrypted payload it never decrypts. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure antivirus inspects the expected application protocols and nonstandard ports as designed.
- Current AV databases are required to identify newly added malware signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to ensure antivirus inspects the expected application protocols and nonstandard ports as designed.
- Protocol options define how FortiGate identifies and processes supported application protocols for inspection. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, review and apply the correct protocol-options profile and port handling for the policy. Protocol options define how FortiGate identifies and processes supported application protocols for inspection.
Question 20
The security team at Datum Corporation wants to troubleshoot file scanning that stops because the object exceeds configured inspection limits. Which FortiGate configuration or action most directly meets that goal? The team will validate the result immediately after the change.
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
- Review and apply the correct protocol-options profile and port handling for the policy
- Review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context
- Maintain FortiGuard antivirus entitlement and signature updates and verify update status
- Review protocol and antivirus oversize or size-limit behavior and tune the limit only after considering resource and security impact
Correct answer: E
Explanation
- Antivirus cannot inspect an encrypted payload it never decrypts. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot file scanning that stops because the object exceeds configured inspection limits.
- Protocol options define how FortiGate identifies and processes supported application protocols for inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot file scanning that stops because the object exceeds configured inspection limits.
- AV logs record detections and the action FortiGate took on the object. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot file scanning that stops because the object exceeds configured inspection limits.
- Current AV databases are required to identify newly added malware signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot file scanning that stops because the object exceeds configured inspection limits.
- Inspection limits can change how oversized objects are handled. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, review protocol and antivirus oversize or size-limit behavior and tune the limit only after considering resource and security impact. Inspection limits can change how oversized objects are handled.
Question 21
An incident at Southridge Video requires the security engineer to confirm whether FortiGate blocked a file because of an antivirus signature. What should be done first? No unrelated security controls should be changed.
- Maintain FortiGuard antivirus entitlement and signature updates and verify update status
- Review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context
- Review protocol and antivirus oversize or size-limit behavior and tune the limit only after considering resource and security impact
- Use full SSL inspection together with the antivirus profile on the matching policy
- Review and apply the correct protocol-options profile and port handling for the policy
Correct answer: B
Explanation
- Current AV databases are required to identify newly added malware signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to confirm whether FortiGate blocked a file because of an antivirus signature.
- AV logs record detections and the action FortiGate took on the object. This directly satisfies the stated requirement.
- Inspection limits can change how oversized objects are handled. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to confirm whether FortiGate blocked a file because of an antivirus signature.
- The encrypted payload must be decrypted before antivirus can inspect the downloaded content. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to confirm whether FortiGate blocked a file because of an antivirus signature.
- Protocol options define how FortiGate identifies and processes supported application protocols for inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to confirm whether FortiGate blocked a file because of an antivirus signature.
Learning point: For this FortiOS 7.6 scenario, review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context. AV logs record detections and the action FortiGate took on the object.
Question 22
For a FortiGate 7.6 deployment at Fabrikam Manufacturing, which option correctly addresses the need to keep malware detection current? The administrator wants a configuration that is easy to audit later.
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
- Use full SSL inspection together with the antivirus profile on the matching policy
- Review and apply the correct protocol-options profile and port handling for the policy
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
- Maintain FortiGuard antivirus entitlement and signature updates and verify update status
Correct answer: E
Explanation
- Antivirus cannot inspect an encrypted payload it never decrypts. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to keep malware detection current.
- The encrypted payload must be decrypted before antivirus can inspect the downloaded content. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to keep malware detection current.
- Protocol options define how FortiGate identifies and processes supported application protocols for inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to keep malware detection current.
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to keep malware detection current.
- Current AV databases are required to identify newly added malware signatures. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, maintain FortiGuard antivirus entitlement and signature updates and verify update status. Current AV databases are required to identify newly added malware signatures.
Question 23
Wingtip Energy has validated routing and basic reachability. The remaining requirement is to troubleshoot malware that passes through only when the traffic is encrypted. Which action should the team take? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
- Review protocol and antivirus oversize or size-limit behavior and tune the limit only after considering resource and security impact
- Review and apply the correct protocol-options profile and port handling for the policy
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
- Use full SSL inspection together with the antivirus profile on the matching policy
Correct answer: D
Explanation
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot malware that passes through only when the traffic is encrypted.
- Inspection limits can change how oversized objects are handled. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot malware that passes through only when the traffic is encrypted.
- Protocol options define how FortiGate identifies and processes supported application protocols for inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot malware that passes through only when the traffic is encrypted.
- Antivirus cannot inspect an encrypted payload it never decrypts. This directly satisfies the stated requirement.
- The encrypted payload must be decrypted before antivirus can inspect the downloaded content. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot malware that passes through only when the traffic is encrypted.
Learning point: For this FortiOS 7.6 scenario, verify full SSL inspection is active and working for the session before changing antivirus signatures. Antivirus cannot inspect an encrypted payload it never decrypts.
Question 24
At Lucerne Publishing, a infrastructure engineer is handling a FortiGate 7.6 change. The requirement is to avoid disabling all antivirus after one false positive. What should the administrator do? The team wants the smallest change that directly addresses the requirement.
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
- Review antivirus security-event logs for the detected threat, action, file or protocol details, and policy context
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
- Review and apply the correct protocol-options profile and port handling for the policy
- Confirm the detection and use the narrowest appropriate exemption or signature handling change
Correct answer: E
Explanation
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid disabling all antivirus after one false positive.
- AV logs record detections and the action FortiGate took on the object. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid disabling all antivirus after one false positive.
- Antivirus cannot inspect an encrypted payload it never decrypts. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid disabling all antivirus after one false positive.
- Protocol options define how FortiGate identifies and processes supported application protocols for inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to avoid disabling all antivirus after one false positive.
- Targeted remediation preserves the rest of the antivirus protection. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, confirm the detection and use the narrowest appropriate exemption or signature handling change. Targeted remediation preserves the rest of the antivirus protection.
Question 25
During a maintenance window at School of Fine Art, the team must scan supported clear-text file transfers for known malware. Which action is the most appropriate? The choice should follow normal FortiOS administration practice.
- Use full SSL inspection together with the antivirus profile on the matching policy
- Review and apply the correct protocol-options profile and port handling for the policy
- Apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior
- Maintain FortiGuard antivirus entitlement and signature updates and verify update status
- Verify full SSL inspection is active and working for the session before changing antivirus signatures
Correct answer: C
Explanation
- The encrypted payload must be decrypted before antivirus can inspect the downloaded content. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan supported clear-text file transfers for known malware.
- Protocol options define how FortiGate identifies and processes supported application protocols for inspection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan supported clear-text file transfers for known malware.
- Antivirus scanning is performed by a security profile on traffic allowed through the policy. This directly satisfies the stated requirement.
- Current AV databases are required to identify newly added malware signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan supported clear-text file transfers for known malware.
- Antivirus cannot inspect an encrypted payload it never decrypts. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to scan supported clear-text file transfers for known malware.
Learning point: For this FortiOS 7.6 scenario, apply an antivirus profile to the matching firewall policy using an inspection mode supported by the required AV behavior. Antivirus scanning is performed by a security profile on traffic allowed through the policy.