Antivirus Flashcards

1
Q

What inspection modes can FortiGate operate in?

A
  • Flow-based
  • Proxy-based
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the default inspection mode?

A

Flow-based

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is required to use antivirus on your FortiGate?

A

An appropriate license

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How does flow-based inspection mode work?

A
  • FortiGate examines the file as it passes through FortiGate
  • User sees a faster response than if proxy-based inspection mode was used
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How would you enable an Antivirus profile?

A

In the firewall policy, under Security Profiles, toggle the antivirus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How does proxy-based inspection mode work?

A
  • FortiGate buffers the traffic and examines it as a whole before determining an action
  • Allows for more points of data than flow-based inspection
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What additional antivirus support does proxy inspection mode offer?

A
  • MAP and SSH protocol inspection
  • Content disarm and reconstruction (CDR)
  • FortiNDR inspection
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

From the user’s end, what happens when a virus is detected?

A

Antivirus block page is displayed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What inspection mode would you use if security was your top priority?

A

Proxy-based inspection mode

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is required to configure protocol port mapping?

A

Proxy-based inspection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What additional granularity is provided by using protocol options?

A

Large files are automatically blocked (threshold can be customized)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are some fixes for common antivirus issues?

A
  • Verify antivirus license, check for updates
  • Correct firewall policy configuration
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What type of inspection mode can be offloaded using CP processors?

A

Flow-based

How well did you know this?
1
Not at all
2
3
4
5
Perfectly