Content Inspection
FCP-FGT-AD-7-6 · 59 questions
- A regional utility's NOC administrator wants FortiGate to buffer entire downloaded files from the corporate billing segment so antivirus can inspect the complete payload and present a custom block page when malware is found, rather than simply resetting the session mid-transfer. Which inspection mode should the policy use to get that behavior?
- A network engineer is designing the firewall policy for the link between a remote substation and the utility's NOC, where throughput and low latency matter more than the richest possible content-inspection feature set. The engineer selects flow-based inspection for that policy. What is the main architectural reason flow-based inspection fits this requirement?
- An OT vendor's application on the grid-operations network uses certificate pinning and breaks whenever its TLS session is decrypted. The NOC team applies certificate inspection instead of deep inspection to that traffic so they can still log destinations by category. What is FortiGate actually able to determine under certificate inspection?
- The utility's security team needs FortiGate to detect malware embedded inside HTTPS downloads on the corporate billing segment, not just identify which domains are being visited. Which SSL inspection approach is required to make that content visible to the antivirus engine?
- After the utility enables a deep-inspection SSL profile on the policy covering NOC administrator workstations, several staff report that their browsers now show certificate warnings on ordinary HTTPS sites. What is the most likely cause, and what should the team do about it?
- The OT vendor's substation application keeps failing under deep inspection because it pins the destination server's exact certificate and rejects any substitute FortiGate presents. The NOC team wants to keep deep inspection active for all other traffic on that policy while letting this one application through untouched. What is the appropriate mechanism?
- A utility security analyst is comparing how antivirus scanning behaves in a flow-based firewall policy versus a proxy-based one for the field-technician VPN segment. Which statement correctly describes flow-based antivirus scanning?
- The back-office work-order dispatch segment uses proxy-based inspection with antivirus enabled, and a field engineer downloads a firmware image far larger than the antivirus profile's configured oversize-file threshold. What is the expected behavior for that download?
- A utility administrator notices that a particular replacement-message behavior available on one firewall policy is not available on another policy carrying an otherwise identical antivirus profile. What most likely explains the difference?
- The billing back-office segment only needs FortiGate to enforce category-based web filtering on HTTPS traffic (blocking known-bad domains) and does not require the firewall to detect malware hidden inside encrypted downloads. Which SSL inspection choice satisfies this requirement with the least decryption overhead?
- A NOC engineer proposes turning off SSL inspection entirely for the whole corporate segment just to stop certificate warnings on the OT vendor's pinned application, instead of adding that one application to the SSL exemption list. What is the main drawback of the engineer's proposed approach?
- When deep inspection is active on the FortiGate protecting the NOC, how does the FortiGate present a certificate to an internal workstation browsing to an external HTTPS site?
- A deep-inspection profile has been running smoothly for over a year on the NOC's outbound policy, with the signing CA certificate already trusted on every workstation. One morning, every workstation on that policy simultaneously starts showing certificate warnings on every HTTPS site, with no configuration change made overnight. What is the most likely cause?
- A utility network architect is choosing an inspection mode for a high-throughput fiber link between two substations that mostly carries routine telemetry and management traffic, where CPU and memory headroom on the FortiGate are limited and full-object buffering is not a priority. Which mode best fits this constraint?
- The utility's compliance team wants FortiGate to block access to a specific URL path on an otherwise-permitted HTTPS site (for example, blocking only a particular page on a general-purpose SaaS site) rather than blocking the whole domain. Which SSL inspection setting is required to make path-level filtering possible?
- A utility security engineer configures antivirus on a proxy-based policy so that when a file download is confirmed infected, FortiGate withholds the file from the requester and presents a substitute notification page rather than merely dropping the connection. Which behavior does this depend on that flow-based inspection does not provide in the same way?
- Rather than manually listing every FQDN belonging to third-party software-update and SaaS vendors the NOC relies on, an administrator wants FortiGate to exempt whole categories of well-known, low-risk destinations from SSL deep inspection. What FortiGate capability supports this without hand-building a custom address list for every vendor?
- The utility's security team is finalizing separate firewall policies for two different traffic types crossing the same FortiGate: general corporate web browsing on the billing segment, and the OT vendor's certificate-pinned application on the substation segment. Which pairing of inspection choices best matches each traffic type's needs?
- The utility's antivirus profile on the corporate billing segment is fully configured and applied to the policy, yet malware embedded inside an HTTPS download from an external site is not being detected. Investigation shows the policy's SSL/SSH inspection profile is set to certificate inspection. What is the most likely explanation for the missed detection?
- Reviewing the utility's overall content-inspection design, an auditor asks why the billing segment uses deep inspection with full antivirus and web filtering, the substation segment uses certificate inspection with an SSL exemption for the OT vendor's pinned application, and the NOC administrator segment uses deep inspection plus a distributed trusted CA certificate. What principle best explains why these three segments are configured differently rather than sharing one SSL/SSH inspection profile?
- Meridian Electric Cooperative's NOC workstation policy applies a web filter profile containing a static URL filter list with a Block entry for one site, while the FortiGuard category that same site belongs to is configured with a Monitor action. When a NOC analyst browses to that site, what happens, and why?
- An administrator adds Meridian Electric Cooperative's OT vendor support portal to the static URL filter list with the Exempt action so field engineers can always reach it. What is the practical effect of choosing Exempt instead of Allow for that entry?
- Meridian Electric Cooperative wants field-service technicians to see a notice before opening a category of sites that is discouraged but sometimes operationally necessary, rather than blocking it outright. Which FortiGuard category action fits this requirement?
- Meridian Electric Cooperative doesn't want to fully block a streaming-video category on back-office workstations, but wants usage capped so it doesn't consume WAN bandwidth all day. Which web filter category action is designed for exactly this?
- Meridian Electric Cooperative wants FortiGate to force safe search on a search engine that back-office staff use over HTTPS, using the web filter profile's safe search option rather than a DNS-based rewrite. What does FortiOS need in place for that enforcement to actually take effect on the HTTPS traffic?
- An administrator at Meridian Electric Cooperative wants to guarantee that one specific vendor domain is always treated a certain way, independent of how FortiGuard's cloud rating service currently classifies it. Which web filter mechanism should the administrator use for that guarantee?
- Meridian Electric Cooperative wants to stop NOC workstations from reaching a risky category of destinations no matter what application or port a user tries to reach them with. Why is a DNS filter profile particularly well suited to that goal, compared to relying on web filtering alone?
- Meridian Electric Cooperative's web filter profile blocks a specific category, and the destination sites are all HTTPS. Which statement correctly distinguishes what FortiGate can enforce on that HTTPS traffic without SSL deep inspection versus with it enabled?
- A field technician's laptop at Meridian Electric Cooperative runs a messaging application configured to use a nonstandard TCP port instead of its usual default. Why is application control still able to identify and act on that traffic, unlike a rule that matched purely on destination port?
- Meridian Electric Cooperative wants to block essentially every application in the Peer-to-Peer category on back-office workstations, but allow one specific internal file-transfer application even though it happens to fall into that same category. How does an application control profile support this?
- Without SSL deep inspection enabled, what is a realistic expectation for application control's ability to identify applications running inside fully encrypted HTTPS sessions?
- Meridian Electric Cooperative wants to restrict which video categories back-office staff can watch on a major video-sharing site. That site is served entirely over HTTPS. What does the video filter profile require in order to make category- or channel-level decisions on that traffic?
- Meridian Electric Cooperative has a FortiGuard category that field technicians occasionally need for legitimate vendor research, but the security team wants access tied to a specific, identifiable person rather than allowed for anyone who happens to click past a notice. Which web filter category action fits this requirement?
- Before deciding whether to block a newly observed web category on substation-facing workstations, a Meridian Electric Cooperative administrator wants to see how often that category is actually being visited without interrupting anyone's browsing yet. Which category action fits this exploratory step?
- NOC administrators notice that FortiGuard category-based web filter actions have stopped taking effect on Meridian Electric Cooperative's FortiGate, even though the web filter profile configuration hasn't changed. Which underlying condition would most directly explain this symptom?
- An administrator at Meridian Electric Cooperative needs a static URL filter entry that matches an entire family of subdomains used by one vendor, not just a single exact address. What capability of the static URL filter list makes this possible?
- Meridian Electric Cooperative uses a proprietary OT vendor protocol on the field-service segment that Fortinet's application signature database does not recognize. The administrator wants a deliberate, configured decision for this kind of unrecognized traffic rather than an accidental default. Where in an application control profile is that decision made?
- When Meridian Electric Cooperative's DNS filter profile blocks a category, browser-based traffic to a blocked domain typically shows the technician a FortiGuard block/landing page, while a non-browser OT client attempting to reach that same blocked domain simply fails to connect with no page shown. What explains this difference?
- Meridian Electric Cooperative's NOC wants to block objectionable video content for staff browsing over HTTPS, in addition to their existing Web Filter profile. How should the administrator configure this in FortiOS 7.6, and what does it require to act on the HTTPS sessions?
- Meridian Electric Cooperative needs one specific page on a shared corporate SaaS domain permitted while blocking every other page on that same domain for back-office users. Why is a DNS filter profile the wrong tool for this specific requirement, even though it could block the whole domain easily?
- A network engineer at a regional electric utility builds and tunes an IPS sensor for the substation segment, but does not touch any existing firewall policy. What happens to traffic entering that segment?
- A field engineer keeps seeing IPS alerts fire and block a legitimate operational polling protocol traveling between the NOC and a substation switching station. The sensor protecting that link covers a broad set of signatures. Which change addresses the false positive with the least collateral impact on the rest of the substation's protection?
- A security engineer is evaluating an IPS signature described as "rate-based" for detecting a flood-style scan attempt against the utility's back-office web application. Which best describes how a rate-based signature differs from a standard signature match?
- Meridian Electric Cooperative is enabling IPS on a substation link for the first time and wants to see which signatures would actually fire against real traffic before any of them are allowed to interrupt substation communications. Which rollout approach fits how FortiGate IPS is designed to be tuned in?
- Which best describes what a file filter profile does within a firewall policy protecting the utility's back-office file-transfer traffic?
- A work-order dispatch system at the utility only accepts image attachments, but an operator renames an executable file to end in ".jpg" hoping to slip it past a simple content check. How does a properly configured file filter profile generally handle this attempt?
- The utility wants to reduce the risk of operational data, such as substation configuration exports, leaving the network through the back-office email gateway. Which capability is purpose-built for identifying that kind of sensitive content within the traffic stream?
- When rolling out a new DLP filter to protect the flow of operational data from the grid-operations network toward the internet-facing back-office segment, which action choice lets the security team observe matches before committing to enforcement?
- After attaching IPS, file filter, and DLP profiles to the policy protecting the substation link, an engineer wants to confirm the profiles are actually evaluating traffic rather than just being present in the policy configuration. What is a reliable way to verify this?
- An IPS signature entry lists attributes such as severity and target operating system. What is the general purpose of these attributes when an administrator is building a sensor for the utility's back-office servers?
- A utility technician emails a password-protected .zip archive containing several files toward the internet-facing gateway. In general terms, why might a file filter profile fail to enforce its file-type rule on the files stored inside that archive?
- The utility wants to catch unusually large exports of operational data leaving the grid-operations segment even without knowing the exact content pattern in advance. Which DLP filter match criterion best supports that goal?
- Two IPS actions available for a matched signature are "block" and "reset." In general terms, what distinguishes "reset" from a plain "block" when a match occurs on TCP traffic?
- An administrator created a DLP profile and confirmed its filters are configured correctly, but traffic matching the sensitive pattern still passes untouched through the firewall policy protecting the back-office email gateway. What is the most likely cause?
- When an administrator adds a predefined IPS signature to a sensor without changing its action, what generally happens?
- For a DLP profile designed to prevent operational data from leaving the grid-operations segment toward the internet, which firewall policy is the correct place to attach it?
- A firewall policy protecting an outbound path from the back-office segment has both a file filter profile and a DLP profile attached. A file being transferred matches a block rule in the file filter profile. What happens to that specific transfer, at minimum?
- A work-order dispatch upload was blocked by the FortiGate protecting the back-office segment, but the operator doesn't know which security profile caused it. What is the most direct way for an engineer to determine which profile — IPS, file filter, or DLP — took the action?
- A utility security team is documenting the roles of IPS, file filter, and DLP profiles for their FortiGate deployment. Which statement correctly distinguishes the three from each other?