exam questions

Exam NSE4_FGT-7.0 All Questions

View all questions & answers for the NSE4_FGT-7.0 exam

Exam NSE4_FGT-7.0 topic 1 question 3 discussion

Actual exam question from Fortinet's NSE4_FGT-7.0
Question #: 3
Topic #: 1
[All NSE4_FGT-7.0 Questions]

Refer to the exhibits to view the firewall policy (Exhibit A) and the antivirus profile (Exhibit B).
Exhibit A.

Exhibit B.

Which statement is correct if a user is unable to receive a block replacement message when downloading an infected file for the first time?

  • A. The flow-based inspection is used, which resets the last packet to the user.
  • B. The volume of traffic being inspected is too high for this model of FortiGate.
  • C. The firewall policy performs the full content inspection on the file.
  • D. The intrusion prevention security profile needs to be enabled when using flow-based inspection mode.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
bccabrera
Highly Voted 1 year, 2 months ago
Selected Answer: A
Study Guide - Antivirus - Antivirus Scanning Modes - Flow-Based Inspection Mode. Two possible scenarios can occur when a virus is detected: - When a virus is detected on a TCP session where some packets have been already forwarded to the receiver, FG resets the connection and does not send the last piece of the file. Although the receiver got most of the file content, the file has been truncated and therefore, can't be opened. The IPS engine also caches the URL of the infected file, so that IF A SECOND ATTEMPT TO TRANSMIT THE FILE IS MADE, THE IPS ENGINE WILL SEND A BLOCK REPLACEMENT MESSAGE to the client instead of scanning the file again. - If the virus is detected at the start of the connection, the IPS engine sends the block replacement message immediately.
upvoted 15 times
chromevandium11
1 year ago
Great explanation, thank you
upvoted 1 times
...
...
raydel92
Most Recent 4 months, 2 weeks ago
Selected Answer: A
Correct: A. The flow-based inspection is used, which resets the last packet to the user.
upvoted 1 times
...
Ibrahimadwan
8 months ago
A is coreect
upvoted 1 times
...
Tcmh
1 year, 3 months ago
Selected Answer: A
A is correct, wording is first time
upvoted 2 times
...
castaway
1 year, 4 months ago
Selected Answer: A
A is correct
upvoted 1 times
...
jlfoul
1 year, 4 months ago
Selected Answer: A
A is correct
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago