Archives are unpacked and files and archives within are scanned separately.
Decompressed files have a separate oversize limit.
Limit can be configured for each protocol separately.
Answer
compressed archives are supported (default is 12 layers) maximum 100 usually.
compressed archives are supported (default is 21 layers) maximum 1000 usually.
compressed archives are supported (default is 100 layers) maximun 1000 usually.
Question 2
Question
What is the default scanning behavior for files over 10MB?
Answer
A. Allow the file without scanning.
B. Block all large files that exceed the buffer threshold.
Question 3
Question
How do you enable botnet protection?
Answer
A. Enable botnet scans under FortiSandbox configuration.
B. Enable botnet scans on external (WAN) facing interfaces.
Question 4
Question
FortiGate models that feature NTurbo (NP4 or NPS) can accelerate antivirus processing to enhance performance.
SoC3 models also support NTurbo
Answer
Config ips global
set np-accel-mode {none | basic } (Enable NTurbo acceleration
Config av global
set np-accel-mode {none | basic } (Enable NTurbo acceleration
Question 5
Question
Can you use NTurbo hardware acceleration for proxy-based inspection mode antivirus scans?
Answer
Yes
No
Question 6
Question
What does the logging of oversized files option do?
Answer
A. Enables logging of all files that cannot be scanned due to oversize limit.
B. Logs all files that are over 5MB.
Question 7
Question
Run the real-time update debug to isolate update-related issues.