ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 31 - NSE8_812 discussion

Report
Export

Which two statements are correct on a FortiGate using the FortiGuard Outbreak Protection Service (VOS)? (Choose two.)

A.
The FortiGuard VOS can be used only with proxy-base policy inspections.
Answers
A.
The FortiGuard VOS can be used only with proxy-base policy inspections.
B.
If third-party AV database returns a match the scanned file is deemed to be malicious.
Answers
B.
If third-party AV database returns a match the scanned file is deemed to be malicious.
C.
The antivirus database queries FortiGuard with the hash of a scanned file
Answers
C.
The antivirus database queries FortiGuard with the hash of a scanned file
D.
The AV engine scan must be enabled to use the FortiGuard VOS feature
Answers
D.
The AV engine scan must be enabled to use the FortiGuard VOS feature
E.
The hash signatures are obtained from the FortiGuard Global Threat Intelligence database.
Answers
E.
The hash signatures are obtained from the FortiGuard Global Threat Intelligence database.
Suggested answer: C, E

Explanation:

The FortiGuard Outbreak Prevention Service (VOS) is a feature that enhances the antivirus scanning capabilities of FortiGate by querying FortiGuard with the hash of a scanned file that is not found in the local antivirus database. If the hash matches a signature in the FortiGuard Global Threat Intelligence database, which contains information about known malware and zero-day threats, the file is deemed to be malicious and blocked by FortiGate. The VOS feature can be used with both proxy-based and flow-based policy inspections, and does not require the AV engine scan to be enabled. Reference:

https://docs.fortinet.com/document/fortigate/6.2.14/cookbook/968606/outbreak-preventionservice

asked 18/09/2024
yusuf sivrikaya
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first