IIRC some operations are based on DNS TTL others are based on how full the relevant RAD cache is...
Relevant resources include:
sk92224: Optimizing the categorization of DNS traffic by changing the Resource Classification Mode, for Anti-Virus and Anti-Bot
sk110214: How to clear DNS cache of HTTP/HTTPS Proxy function without 'cpstop'
sk89340: Traffic latency might be caused by Anti-Bot / Anti-Virus resource categorization mode set to 'Hold'
sk74120: Why Anti-Bot and Anti-Virus connections may be allowed even in Prevent mode
sk92264: ATRG: Anti-Bot and Anti-Virus
sk90422: How to modify URL Filtering cache size?