Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam NSE4_FGT-7.2 topic 1 question 20 discussion

Actual exam question from Fortinet's NSE4_FGT-7.2
Question #: 20
Topic #: 1
[All NSE4_FGT-7.2 Questions]

Which three statements explain a flow-based antivirus profile? (Choose three.)

  • A. Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection.
  • B. If a virus is detected, the last packet is delivered to the client.
  • C. The IPS engine handles the process as a standalone.
  • D. FortiGate buffers the whole file but transmits to the client at the same time.
  • E. Flow-based inspection optimizes performance compared to proxy-based inspection.
Show Suggested Answer Hide Answer
Suggested Answer: ADE 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
MengtingLiang
2 weeks, 6 days ago
ADE Flow-based inspection mode uses a hybrid of the scanning modes available in proxy-based inspection: the default scanning mode and the legacy scanning mode. Optimized performance compared to proxy-basedscanProxy-based. FortiGate buffers the whole file but transmits it to the client simultaneously. If a virus is detected, the last packet is dropped and the connection is reset.
upvoted 1 times
...
LAFNELL
6 months, 3 weeks ago
Selected Answer: ADE
D as formulate is definitely not a correct answer. FortiOS 7.2 Admin Guide Page 1086. You can read "When a firewall policy's inspection mode is set to flow, traffic flowing through the policy will not be buffered by the FortiGate". Below the link https://docs.fortinet.com/document/fortigate/7.2.0/administration-guide/659145 So, as C is not correct too, i think there is a mistake on the formulation of answer D which should be the correct answer.
upvoted 1 times
...
raydel92
8 months, 1 week ago
Selected Answer: ADE
A. Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection. D. FortiGate buffers the whole file but transmits to the client at the same time. E. Flow-based inspection optimizes performance compared to proxy-based inspection. Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html
upvoted 1 times
...
Vic2911
8 months, 2 weeks ago
Selected Answer: ACE
A. Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection. (correct) B. If a virus is detected, the last packet is delivered to the client. (Wrong, if a virus is detected the packet is dropped and a RST packet is sent to client) C. The IPS engine handles the process as a standalone.(since B and D are wrong, C must be correct) D. FortiGate buffers the whole file but transmits to the client at the same time. (wrong, is flow-based inspection mode the fortigate does not buffer the packets, it delivers them to the client immediately. When the last packet arrives, FortiGate caches it and puts it on hold while performing AV scanning by the AV engine) E. Flow-based inspection optimizes performance compared to proxy-based inspection. (correct)
upvoted 1 times
Vic2911
8 months, 2 weeks ago
I misread the D sentence. D answer is correct
upvoted 3 times
...
...
Slash_JM
8 months, 2 weeks ago
Selected Answer: ADE
FortiGate Security 7.2 Study Guide p.350
upvoted 2 times
...
D1360_1304
9 months, 2 weeks ago
A, D and E, FortiGate Security 7.2 Study Guide Page 350
upvoted 2 times
...
Danny_B
12 months ago
Selected Answer: ADE
7.2 SEC 350
upvoted 2 times
...
PaulGo
1 year, 1 month ago
Selected Answer: ADE
Correct answer is A, D, E
upvoted 1 times
...
BoostBoris
1 year, 3 months ago
Selected Answer: ADE
A: Flow-based inspection mode uses a hybrid of the scanning modes available in proxy-based inspection D: the IPS engine reads the payload of each packet, caches a local copy, and forwards the packet to the receiver at the same time. some operations can be offloaded to SPUs to improve performance (not C) E: If performance is your top priority, then flow inspection mode is more appropriate.
upvoted 2 times
...
chromevandium11
1 year, 4 months ago
Selected Answer: ADE
ADE is correct.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...