Antivirus Flashcards
What is the order of scanning operations for antivirus?
Antivirus scan (exact match)
Grayware (unwanted program)
AI Scan (new, unknown)
What are the two Antivirus Signature Databases?
Extended: default (signatures for viruses in the most recent months)
Extreme: (all known viruses and old OS support) (does not work on all models)
What does CDR stand for?
Content disarm and reconstruction
For AV, what is the difference between default scan mode and the legacy scanning mode?
Default enhances the scanning of nested archive files without buffering the container file. Where as legacy mode buffers the whole container file, and then scans it.
How do packets flow in flow-based inspection mode?
Packets are buffered and sent to the host, except the last packet. FTG sends all the packets to the IPS engine reassembles the file, sends it to the AV engine, if no virus, then send last packet to host. If there is a virus the last packet is not sent and the connection truncated.
Do clients have to wait for the AV scan to finish in proxy inspection mode?
Yes, however you can turn on client comfort to pass a block or two so the connection is kept open
How does buffering work in Proxy Mode Inspection for AV?
The entire file is buffered
What is stream-based AV scanning?
decompresses large files and then scans and extracts them at the same time. Viruses are detected even if they are in the middle or towards the end of a large archive.
What must be configured to enable proxy based AV inspection?
You must select proxy based in both the AV profile and FW policy.
What additional AV scanning options are available if using proxy AV scanning mode?
MAPI and SSH inspection
Sanitize MS office and PDFs with CDR
By default, what does FortiOS do with oversized files?
it does not scan them
Can FTG decompress archive files with a password?
no
How many layers of compression will FTG scan for viruses? By default?
12
Does Fortinet recommend deep-inspection for SSL/SSH for AV Scanning?
Yes
What FTG can offload Flow-based AV scanning
Models that feature Turbo (NP6 or NP7)