QuestionQ3

Network Security

Refer to the exhibits.

Question Image

Question Image

A FortiSASE administrator configured an antivirus profile in the security profile group and applied it to the internet-access policy. Remote users can still download the eicar.com-zip file from https://eicar.org.

Which FortiSASE configuration is allowing users to download it?

  • A Web filter is allowing the URL.
  • B Deep inspection is not enabled.
  • C Application control is exempting all the browser traffic.
  • D Intrusion prevention is disabled.
Explanation

FortiSASE requires deep SSL inspection to decrypt and inspect content within HTTPS traffic for antivirus scanning. Certificate inspection examines only information up to the SSL/TLS layer, so it cannot inspect and block the EICAR ZIP payload downloaded over HTTPS. Web filtering can still allow or block the URL based on its category without inspecting that encrypted file content.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!