ExamGecko
Question list
Search
Search

Question 12 - NSE4_FGT-7.2 discussion

Report
Export

Which two statements explain antivirus scanning modes? (Choose two.)

A.
In proxy-based inspection mode, files bigger than the buffer size are scanned.
Answers
A.
In proxy-based inspection mode, files bigger than the buffer size are scanned.
B.
In flow-based inspection mode, FortiGate buffers the file, but also simultaneously transmits it to the client.
Answers
B.
In flow-based inspection mode, FortiGate buffers the file, but also simultaneously transmits it to the client.
C.
In proxy-based inspection mode, antivirus scanning buffers the whole file for scanning, before sending it to the client.
Answers
C.
In proxy-based inspection mode, antivirus scanning buffers the whole file for scanning, before sending it to the client.
D.
In flow-based inspection mode, files bigger than the buffer size are scanned.
Answers
D.
In flow-based inspection mode, files bigger than the buffer size are scanned.
Suggested answer: B, C

Explanation:

An antivirus profile in full scan mode buffers up to your specified file size limit. The default is 10 MB. That is large enough for most files, except video files. If your FortiGate model has more RAM, you may be able to increase this threshold. Without a limit, very large files could exhaust the scan memory. So, this threshold balances risk and performance. Is this tradeoff unique to FortiGate, or to a specific model? No. Regardless of vendor or model, you must make a choice. This is because of the difference between scans in theory, that have no limits, and scans on real-world devices, that have finite RAM. In order to detect 100% of malware regardless of file size, a firewall would need infinitely large RAM--something that no device has in the real world. Most viruses are very small. This table shows a typical tradeoff. You can see that with the default 10 MB threshold, only 0.01% of viruses pass through.

FortiGate Security 7.2 Study Guide (p.350 & 352): 'In flow-based inspection mode, the IPS engine reads the payload of each packet, caches a local copy, and forwards the packet to the receiver at the same time. Because the file is ransmitted simultaneously, flow-based mode consumes more CPU cycles than proxy-based.' 'Each protocol's proxy picks up a connection and buffers the entire file first (or waits until the oversize limit is reached) before scanning. The client must wait for the scanning to finish.'

asked 18/09/2024
Med Amine Aloui
26 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first