BlackFriday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet Exam FCSS_SASE_AD-23 Topic 3 Question 13 Discussion

Actual exam question for Fortinet's FCSS_SASE_AD-23 exam
Question #: 13
Topic #: 3
[All FCSS_SASE_AD-23 Questions]

Refer to the exhibits.

A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to download the eicar.com-zip file from https://eicar.org. Traffic logs show traffic is allowed by the policy.

Which configuration on FortiSASE is allowing users to perform the download?

Show Suggested Answer Hide Answer
Suggested Answer: A

Based on the provided exhibits and the configuration details, the reason why users are still able to download the eicar.com-zip file despite having an antivirus profile applied is due to the Web Filter allowing the traffic. Here is the step-by-step detailed explanation:

Web Filtering Logs Analysis:

The logs show that the traffic to the destination port 443 (which is HTTPS) is allowed and the security event triggered is Web Filter.

The log details indicate that the URL belongs to an allowed category in the policy and thus, the traffic is permitted by the Web Filter.

Security Profile Group Configuration:

The Web Filter with Inline-CASB section indicates that the site www.eicar.org is being monitored (93 occurrences) and not blocked.

Since the Web Filter is set to allow traffic from this site, the antivirus profile will not block it because the Web Filter decision takes precedence.

Antivirus Profile Configuration:

Although the antivirus profile is configured, the logs do not show any antivirus actions being triggered. This indicates that the web filter is overriding the antivirus action.

Policy Configuration:

The policy named 'Web Traffic' shows that it has logging enabled and is set to accept traffic.

The profile group 'SIA' applied to this policy includes both Web Filter and Antivirus settings. However, since the Web Filter is allowing the traffic, the antivirus profile does not get the chance to inspect it.


FortiGate Security 7.2 Study Guide: Provides details on the precedence of web filtering over antivirus in security profiles.

Fortinet Knowledge Base: Detailed explanation of web filtering and antivirus profiles interaction.

Contribute your Thoughts:

Lucy
25 days ago
I bet the admin is still trying to figure out how to spell 'FortiSASE' correctly. That's the real problem here.
upvoted 0 times
...
Dyan
26 days ago
IPS is disabled? That's a rookie mistake. You can't just leave that off and expect everything to work properly.
upvoted 0 times
Suzi
5 days ago
B) IPS is disabled in the security profile group.
upvoted 0 times
...
Leonora
11 days ago
A) Web filter is allowing the traffic.
upvoted 0 times
...
...
Twana
2 months ago
Maybe the HTTPS protocol is not enabled in the antivirus profile.
upvoted 0 times
...
Stevie
2 months ago
Haha, looks like the admin forgot to enable the force certificate inspection. They must be new to this stuff!
upvoted 0 times
Geoffrey
22 days ago
Definitely, security is key in these situations.
upvoted 0 times
...
Titus
29 days ago
Maybe they should double-check their configurations next time.
upvoted 0 times
...
Eve
1 months ago
Yeah, that's a rookie mistake.
upvoted 0 times
...
Rochell
1 months ago
Looks like someone forgot to enable force certificate inspection.
upvoted 0 times
...
...
Angelo
2 months ago
I believe IPS is disabled in the security profile group.
upvoted 0 times
...
Twana
2 months ago
I think the web filter is allowing the traffic.
upvoted 0 times
...
Minna
2 months ago
The web filter must be the issue here. It's probably not configured to block the EICAR file download.
upvoted 0 times
Shayne
1 months ago
The web filter must be the issue here. It's probably not configured to block the EICAR file download.
upvoted 0 times
...
Caitlin
1 months ago
A) Web filter is allowing the traffic.
upvoted 0 times
...
...
Dortha
2 months ago
I think the HTTPS protocol is the culprit. The antivirus profile needs to be set up to inspect HTTPS traffic.
upvoted 0 times
...

Save Cancel