For the official Microsoft topic on this subject, see Configuring the transport scan on the Microsoft Technical Library.
*******************************
In Forefront Protection 2010 for Exchange Server, there are various configuration settings that you can adjust for the transport scan in order to meet the needs of your environment. These include selecting the number of scan engines to use for each scan, setting the action to take when malware is detected, and specifying whether or not to quarantine detected files.
To configure the transport scan
In the Forefront Protection 2010 for Exchange Server Administrator Console, click Policy Management, and under Antimalware, click Hub - Transport (if you are using an Edge Transport server, Edge - Transport appears instead of Hub - Transport).
In the Antimalware - Hub Transport pane, under the General Settings section, configure the following settings:
In the Antimalware - Hub Transport pane, under the Engines and Performance section, select the number of scan engines that should be used for this scan.
In the Antimalware - Hub Transport pane, under the Scan Actions section, configure the following settings:
You can configure the following additional settings located under the Additional Options section of the Antimalware - Hub Transport pane. Click Save after making any changes to your settings.
Set-FseTransportScan –IllegalMIMEHeaderQuarantine $false