QuestionQ51

System Configuration

You are asked to configure a FortiSandbox to use the real-time anti-phishing (RTAP) feature. After configuring the scan profile, testing shows that URLs are not being submitted to the RTAP service.

Based on the exhibits (Scan Profile Pre-Filter tab, Scan Profile VM Association tab, and Scan Profile Advanced tab), what could cause this issue?

Question Image

Question Image

Question Image

  • A The URL option is not selected as a Web file type.
  • B The URLs are not designated for active content pre-scan.
  • C The VM scan timeout for URLs should be at least 300 to provide enough time for a FortiGuard response.
  • D The WEBLink file type is not selected in the profile.
Explanation

According to FortiSandbox documentation on Real-Time Anti-Phishing, a URL can only be forwarded to the RTAP cloud service if the scan profile's VM Association tab has the WEBLink file type associated with a VM image, since the URL must first be submitted to a sandboxing VM for dynamic analysis before RTAP evaluation occurs. WEBLink (the URL-detection file type) is separate from the 'Web' file type group, which only covers files such as htm, js, lnk, and url that represent shortcuts/embedded links rather than actual URL submissions. If WEBLink is not selected/associated with a VM image in the profile, URLs never enter the VM scan pipeline and therefore are never sent to the RTAP service, even though URL is enabled in the Pre-Filter tab and the Real-time Zero-Day Anti-Phishing Service toggle is enabled under Advanced settings.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!