View all questions & answers for the NSE 4 - FortiOS 7.6 Administrator Exam Materials exam


Question 18 Discussion

A network administrator enabled antivirus and selected an SSL inspection profile on a firewall policy. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and does not block the file, allowing it to be downloaded. The administrator confirms that the traffic matches the configured firewall policy. What are two reasons for the failed virus detection by FortiGate? (Choose two answers)

  • A. The selected SSL inspection profile has certificate inspection enabled.
  • B. The website is exempted from SSL inspection.
  • C. The EICAR test file exceeds the protocol options oversize limit.
  • D. The browser does not trust the FortiGate self-signed CA certificate.
Correct Answer: A,B

Brave-Dump Clients Votes

AB 60%
BC 20%
BD 20%

Comments



Capi 2025-10-31 01:19:50

Selected Answers: B, C


For me it should be B and C no?
A) Not true because if ssh inspection was enabled the FGT could have decrypted the file and see that it cointains virus.
B) True, if the site is exempted thenthe FGT can't see if what the file contains
C)If the file is over the threshold configured then it's not inspected. True
D) NO correlation
  • imade 2025-11-20 00:44:38
    read the A question again : its says that the certificate inspection is on and not deep ssl inspection is on.


Haitham Saleh Aldhabiani 2025-11-05 20:45:50

Selected Answers: B, D


B,D are corrected


imade 2025-11-20 00:44:42

Selected Answers: A, B


A. certificate inspection is not deep ssl inspection hence no inspection of the packet would happen since it is encrypted.
b. if the https site is in exampted list then yes it is a valid reason


imade 2025-11-20 00:44:42

Selected Answers: A, B


A. certificate inspection is not deep ssl inspection hence no inspection of the packet would happen since it is encrypted.
b. if the https site is in exampted list then yes it is a valid reason


Anonymous User 2026-01-12 16:37:43

Selected Answers: A, B


AB - website is exempted (we don't know why), it just is.