Antivirus scan techniques (Choose 3).
Antivirus scan
Grayware scan
Heuristics scan
Fortiguard scan
Suspicious scan
Which databases can be manually selected for use in antivirus scanning?
a. Normal, Extended, and Extreme
b. Quick, Normal, and Extreme
What antivirus database does quick scan mode use?
a. Compact
b. Extended
To detect a virus, the antivirus engine must match file with signature <pattern>
Each vendor uses different detection engines and signatures, such as: (Select 6)
MD5
CRC
Combinations of file attributes
Binary values in some areas
Encryption keys
Parts of code
Binary of files attibutes
Combinations of values in some areas
- Detects and eliminates malware in real time Stops threats from spreading - Preserves the client reputation of your public IP
-Uses grayware signatures -Detects and blocks unsolicited programs -Antivirus actions apply
-Looks for virus-like code (Example; Modifies registry to restart itself after reboot) -Counts virus-like attributes -If greater than a threshold, file is suspicious -False positives possible
The heuristics scan is an optional feature that must be enabled via GUI.
If all antivirus features are enabled, FortiGate applies the following scanning order:
antivirus scan > grayware scan > heuristics scan.
antivirus scan > heuristics scan > grayware scan.
You can update your FortiGate's antivirus database using the push method, schedule method, or both methods
You can verify the update status and signature versions from the Fortiguard page on the GUI or you can run :
diagnose autoupdate status and diagnose autoupdate versions on the CLI.
get autoupdate status and get autoupdate versions on the CLI.
Fortiguard antivirus databases: includes common recent attacks and is available on all models
Normal
Extended
Extreme
Fortiguard antivirus databases: includes normal plus additional recent non-active viruses
Fortiguard antivirus databases: includes extended plus additional dormant viruses *Is only available on select FortiGate models.
Quick Scan-Only available in ________ mode with quick scan option enabled - FortiOS automatically uses a compact signature database if quick scan is applied
flow inspection
proxy