Be able to map a threat scenario to the right Fortinet components: IPS sensor plus automation stitch for auto-blocking, FortiSIEM or FortiAnalyzer for correlation, FortiEDR for endpoint containment. The key is pairing the correct trigger with the correct response action.
Start practicing
Advanced Threat Protection — choose a session length
Free · No account required
Domain overview
This domain covers Fortinet's Advanced Threat Protection tooling on FortiGate and Fabric: IPS sensors and custom signatures, anomaly detection, automated threat response via automation stitches and quarantine, and event correlation through FortiAnalyzer and FortiSIEM. Questions are scenario-based, asking you to pick the correct components, features, or products that satisfy a stated security outcome.
Exam objectives
Configuring IPS sensors, custom signatures, and protocol anomaly detection on FortiGate
Building automation stitches with triggers and actions to block source IPs automatically
Using FortiAnalyzer and FortiSIEM for event collection, correlation, and unified threat views
Deploying FortiEDR and FortiClient EMS for endpoint detection, response, and automated containment
Choosing automation stitches alone when the scenario also requires an IPS sensor with the right severity trigger and action.
Confusing FortiAnalyzer log aggregation with FortiSIEM correlation, or picking FortiSandbox for event correlation it does not perform.
Assuming anomaly detection is a separate module rather than an IPS sensor feature configured with protocol anomaly signatures.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company is deploying FortiGate with Advanced Threat Protection (ATP) and wants to block advanced malware that uses encrypted C2 communications. Which security profile should be configured to perform SSL inspection and detect malicious traffic?
2A network administrator notices that several endpoints are infected with ransomware despite having FortiGate ATP enabled. The logs show that the files were downloaded over HTTPS, and the antivirus profile did not detect them. What is the most likely reason?
3A security engineer is troubleshooting a scenario where FortiGate is not blocking a known malicious URL categorized as 'Malware'. The web filtering profile is configured with 'monitor all' for the Malware category. What change should be made to block the URL?
4A company wants to detect and block phishing emails that contain malicious links. Which FortiGate security profile should be used?
5Refer to the exhibit. A user reports that accessing a legitimate HTTPS website is blocked. The FortiGate logs show that the connection was denied by the antivirus profile. What is the most likely cause?
6What is the primary purpose of Content Disarm and Reconstruction (CDR) in FortiGate's antivirus features?
7What is the primary function of FortiDeceptor in a network security architecture?
8An administrator configures an automation stitch on FortiGate to automatically block an IP address when a specific IPS signature triggers. What must be configured as the trigger and action?
9What is the role of FortiGuard Outbreak Prevention in FortiGate's security suite?
10An organization deploys FortiEDR to protect endpoints. Which component is responsible for collecting and sending telemetry data to the FortiEDR management console?
11An administrator runs the following CLI output: 'diagnose sys session filter dport 443' and sees 'proto=6 proto_state=01 duration=3600 expire=3599'. Which statement BEST describes the session?
12A company wants to protect its internal users from malicious files attached to emails. Which FortiGate feature should be configured to inspect SMTP traffic for malware?
13A FortiGate admin sees the following log: 'Action=blocked, Service=HTTP, Application=Outbreak, File=invoice.doc, ThreatScore=95'. What is the MOST likely explanation for this block?
14Which FortiGate security feature can reconstruct files to remove potentially malicious content while preserving the file's usability?
15An administrator needs to deploy a honeypot solution to detect and deceive attackers inside the network. Which Fortinet product is BEST suited for this purpose?
16A FortiGate administrator configures a custom IPS signature with the pattern 'attack' in the HTTP request URI. After applying the signature, no alerts are generated even though the traffic matches. What is the MOST likely cause?
17Which technology uses DMARC reports to help administrators identify unauthorized use of their email domain?
18An administrator wants to create an automation stitch that sends a webhook notification when an IPS attack is detected. Which trigger and action should be used?
19A FortiGate is configured with a WAF profile to protect a web server. The administrator notices that SQL injection attacks are still reaching the server despite the WAF being enabled. What is the MOST likely reason?
20An administrator runs 'diagnose ips anomaly http' and sees many entries with 'type=SQLi' and 'score=0'. What does a score of 0 indicate?
21An administrator wants to configure FortiGate to automatically block a source IP when a high-severity IPS event is detected. Which TWO components must be configured? (Choose two.)
22Which FortiClient ATP feature provides protection against zero-day malware by monitoring process behavior and blocking suspicious activities at the endpoint?
23A security administrator wants to block email spoofing attacks against their organization's domain. They configure SPF, DKIM, and DMARC records. Which protocol authenticates the domain of the email sender by verifying the email's signature against a public key published in DNS?
24An organization wants to deploy a web application firewall (WAF) to protect a public-facing web application. They are evaluating FortiGate versus FortiWeb. Which of the following is a key advantage of using FortiWeb over FortiGate for WAF functionality?
25A FortiGate administrator wants to implement Content Disarm and Reconstruction (CDR) for email attachments. Which security profile must be configured to enable CDR?
26During a security incident, the SOC team receives an alert from FortiSIEM about a user accessing a known malicious IP. The team wants to automatically block the IP on the FortiGate. Which FortiGate feature can be used to create an automated response based on a threat intelligence feed?
27Which Fortinet product is designed specifically to detect and deceive attackers by creating decoy systems and luring them away from real assets?
28Which FortiMail advanced feature allows the administrator to rewrite URLs in email bodies to redirect users to a safe scanning service when they click on a link?
29What is the primary purpose of FortiGuard Outbreak Prevention service?
30A security engineer wants to implement advanced threat protection for email using FortiMail. Which THREE features should be enabled to provide comprehensive protection against sophisticated email threats? (Choose three.)
31An administrator is investigating a security incident where a workstation is communicating with a known command and control (C2) server. The FortiGate has IPS enabled but did not block the traffic. Which TWO configuration issues could explain why the IPS did not detect the C2 communication? (Choose two.)
32An administrator configures FortiSandbox inline scanning for HTTP traffic. They notice that files uploaded via HTTP are being scanned but no verdict is being returned, causing delays. What is the MOST likely cause?
33A network administrator wants to block known malicious IP addresses using threat intelligence feeds on FortiGate. Which feature should they use?
34An administrator runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?
35A company is deploying FortiClient ATP to protect endpoints. They want to block ransomware behavior in real time. Which FortiClient feature should be enabled?
36An organization wants to prevent zero-day attacks by using Content Disarm and Reconstruction (CDR) on email attachments. Which Fortinet product provides this capability?
37An administrator wants to detect lateral movement and early stages of an attack using decoy systems that mimic production assets. Which Fortinet product should they deploy?
38Which Fortinet product provides endpoint detection and response (EDR) capabilities, including automated threat containment?
39An administrator configures email authentication (SPF, DKIM, DMARC) on FortiMail. They find that legitimate emails are being marked as spam by FortiMail. The SPF check passes but DKIM fails. What could be the issue?
40An administrator needs to enable automation stitches to automatically block a malicious IP address detected by FortiSandbox. Which two components are required? (Choose two.)
41An administrator is configuring FortiMail to improve email security. Which three of the following features are part of FortiMail's advanced threat protection? (Choose three.)
42What is the primary function of Content Disarm and Reconstruction (CDR) in FortiGate's antivirus profile?
43A FortiGate administrator notices that traffic classified as 'unknown' by the antivirus is being allowed. The administrator wants to ensure that such files are submitted to FortiSandbox for analysis and blocked until a verdict is received. Which configuration is required?
44A company uses FortiGate as a web application firewall (WAF) to protect a public web server. The security team wants to block SQL injection attacks. Which WAF signature category should the administrator enable?
45What is the purpose of FortiDeceptor in an enterprise security architecture?
46An administrator wants to use FortiGate to automatically block traffic if FortiEDR detects a threat on an endpoint. Which feature should the administrator configure?
47What is the primary benefit of using FortiClient with ATP features in conjunction with FortiGate?
48A security team is configuring FortiMail for email security. They want to ensure that incoming emails are authenticated using SPF, DKIM, and DMARC, and that emails failing authentication are quarantined. Which THREE settings must be configured in FortiMail? (Choose three.)
49An organization wants to prevent users from downloading malicious files from the internet. Which FortiGate security profile should be applied to the outbound firewall policy to block files based on their hash if they have been identified as malicious by FortiSandbox?
50An admin configures Content Disarm and Reconstruction (CDR) on FortiGate to protect against malicious macros in Office documents. After applying the CDR profile to a firewall policy, users complain that documents are not being delivered. What is the most likely cause?
51Which FortiGate IPS feature allows administrators to create rules that detect network traffic patterns deviating from normal protocol behavior?
52An admin wants to create a custom IPS signature to detect a specific exploit that sends a string 'EXPLOIT' in the HTTP Host header. Which signature syntax is correct?
53A company uses FortiWeb to protect its web application. They want to block SQL injection attempts. Which FortiWeb feature should be configured to inspect HTTP requests for malicious SQL patterns?
54What does FortiGuard Outbreak Prevention use to protect against newly discovered malware outbreaks before traditional signatures are available?
55An admin receives an email from FortiMail regarding a message that was rejected due to SPF failure. What does this indicate about the email?
56A security analyst wants to use automation stitches on FortiGate to automatically block IP addresses that trigger an IPS signature for 'SSH Brute Force'. Which two components are required to create this automation stitch? (Choose two.)
57An organization wants to implement multiple layers of defense against advanced persistent threats. Which three Fortinet solutions would be most effective in an ATP strategy? (Choose three.)
58A network admin is troubleshooting why FortiGate's antivirus is not detecting a known malware sample. The sample is detected by other scanners. Which two checks should the admin perform? (Choose two.)
59An administrator wants to block a zero-day malware outbreak detected by FortiGuard. Which feature should be configured to automatically block the threat across all enabled FortiGate devices?
60A FortiGate admin configures an automation stitch to send an email alert when a high-severity IPS event occurs. The trigger is 'IPS Event' and the action is 'Email'. After testing, no email is sent despite events being logged. What is the most likely cause?
61An administrator sees the following log entry: 'id=13593 msg="CDR: File attachment sanitized"' Which feature generated this log?
62Which Fortinet product is specifically designed to deploy decoys and lures to detect lateral movement and early-stage attacks inside the network?
63Which Fortinet solution collects and correlates security events from multiple sources to provide a unified view of threats across the network?
64A network admin wants to use FortiClient's advanced threat protection features to detect ransomware behavior on endpoints. Which FortiClient feature should be enabled?
65Which feature on FortiGate uses machine learning to detect never-before-seen malware based on file characteristics?
66An administrator configures a WAF profile on FortiGate to protect a web application. However, the administrator notices that SQL injection attacks are not being blocked. What should the administrator check first?
67An organization uses FortiWeb to protect its web applications. The security team wants to block requests that contain a specific custom pattern in the URL. Which feature should be used?
68Which FortiGate security feature removes potentially malicious active content from files (e.g., macros, scripts) before delivering them to end users?
69An administrator wants to integrate FortiGate with an external threat intelligence feed to block known malicious IP addresses automatically. Which object should be used to consume the feed?
70A FortiGate administrator is troubleshooting why a custom IPS signature is not triggering on traffic matching the pattern. Which TWO checks should be performed?
71A company wants to use FortiMail to implement email authentication to prevent spoofing. Which THREE mechanisms should be configured in FortiMail's Authentication Profile?
72An administrator wants to create an automation stitch that responds to a high-severity IPS event by blocking the attacker IP. Which THREE components are required to build this automation stitch?
73An admin wants to block malicious files detected by FortiSandbox at the FortiGate level. Which configuration is required on the FortiGate to automatically block files based on FortiSandbox verdict?
74Which FortiClient feature is specifically designed to prevent the execution of unknown malware by analyzing behavior in real-time?
75A company uses an advanced antivirus profile with machine learning engine enabled. After a recent outbreak, several files that were previously undetected are now flagged. How does the outbreak prevention feature help in this situation?
76An admin wants to ensure that office documents (e.g., Word, Excel) downloaded from the internet are safe before users open them. Which feature should be used to remove potentially malicious macros and active content?
77An IPS administrator wants to detect a new custom attack that sends malformed HTTP headers. The attack pattern is a specific sequence of bytes that is not covered by existing signatures. What is the BEST way to detect this attack on FortiGate?
78A FortiGate is configured with an IPS sensor that has protocol anomaly detection enabled. The admin notices that legitimate VoIP traffic (SIP) is being blocked. Which action should the admin take to reduce false positives?
79An email security administrator wants to prevent attackers from spoofing the company's domain. Which email authentication mechanism should be configured to allow receiving servers to verify that emails claiming to be from the domain are sent from authorized mail servers?
80Which Fortinet product is designed to deploy decoy systems to lure attackers and detect lateral movement within the network?
81An organization wants to implement a solution that can detect and automatically respond to threats across multiple Fortinet security products. Which product should they use?
82A security analyst wants to use automation stitches on FortiGate to automatically block an IP address when a critical severity event is logged. Which TWO components are essential to create this automation stitch? (Choose two.)
83An organization is deploying FortiEDR to enhance endpoint protection. Which THREE capabilities does FortiEDR provide? (Choose three.)
84A FortiGate administrator wants to use threat intelligence feeds to block known malicious IP addresses. Which TWO steps are required to accomplish this? (Choose two.)
85A network administrator wants to ensure that files downloaded from the internet are analyzed by FortiSandbox before being delivered to the client. The FortiGate is configured with a FortiSandbox connection and an antivirus profile. Which setting must be enabled in the antivirus profile to submit files to FortiSandbox?
86What is the primary purpose of Content Disarm and Reconstruction (CDR) in advanced antivirus protection?
87An administrator configures a custom IPS signature to detect traffic to a specific malicious domain. Which syntax is correct for a custom IPS signature in FortiGate?
88A company uses FortiMail for email security. They want to prevent email spoofing by verifying that incoming emails originate from authorized servers. Which email authentication method should be configured on FortiMail to check the sending server's IP against a published SPF record?
89An administrator configures an automation stitch to respond to a high severity event. The trigger is 'event' and the action is 'CLI script'. What must be defined for the action to execute properly?
90Which of the following best describes the function of FortiDeceptor in an enterprise network?
91A FortiGate is configured with an antivirus profile that has the machine learning engine enabled. An administrator notices that some files are being detected by the ML engine but the verdict is 'probably clean'. What does this verdict indicate?
92What is the primary difference between using a Web Application Firewall (WAF) on FortiGate versus using FortiWeb?
93An administrator wants to automatically block a file that FortiSandbox has determined to be malicious. The FortiGate is configured with an antivirus profile that includes FortiSandbox submission. Which verdict action should be set to 'block' in the antivirus profile to achieve this?
94A company wants to receive threat intelligence feeds from external sources to enhance their FortiGate's protection. Which method should be used to integrate external threat feeds into FortiGate?
95An administrator needs to configure advanced email security on FortiMail to protect against phishing and spoofing. Which THREE features should be enabled to achieve comprehensive email authentication?
96A company has deployed FortiClient with advanced threat protection (ATP) features. Which TWO capabilities does FortiClient ATP provide beyond basic antivirus?
97A network administrator notices that FortiGate is not blocking a known malicious file that was submitted to FortiSandbox and received a 'malicious' verdict. The firewall policy includes a FortiSandbox inline scan profile. What is the MOST likely cause?
98A FortiGate administrator wants to ensure that files in email attachments are disarmed before delivery. Which security feature should be configured in the antivirus profile?
99An administrator wants to secure email traffic by ensuring that incoming emails are verified against the sender's domain SPF record. Which email authentication method provides this verification?
100An administrator configured FortiGate to forward suspected malicious files to FortiSandbox. They set the action to 'block' for malicious verdicts. Some files are being blocked, but others with a 'clean' verdict are allowed. However, they notice that some files that should have been sent to FortiSandbox are not being forwarded. Which reason is MOST likely?
101Which feature in FortiMail provides an additional layer of protection by analyzing the behavior of email attachments in a sandbox environment?
102An administrator is configuring FortiDeceptor to detect threats within the network. Which TWO statements about FortiDeceptor are correct?
103An administrator wants to protect against zero-day malware that has not yet been discovered by signature-based detection. Which TWO technologies can help mitigate such threats?
104An administrator is configuring FortiMail to be more secure against advanced email threats. Which THREE features should they enable to protect against email-based phishing attacks?
105A security administrator is configuring FortiSandbox integration to automatically block malicious files detected in email attachments. Which TWO actions are required to achieve this integration?
106A network security team is evaluating options for web application security. They need to protect a critical web application from SQL injection and cross-site scripting (XSS) attacks, and they require granular control over HTTP request parameters. Which THREE factors should influence their decision between using FortiGate's WAF profiles versus deploying a dedicated FortiWeb appliance?
107An organization wants to implement email authentication to prevent spoofing and phishing attacks. They use FortiMail as their email security gateway. Which THREE mechanisms should they configure to achieve comprehensive email authentication?
108An administrator is configuring FortiGate automation stitches to respond to a detected ransomware outbreak. The trigger is a high severity event from FortiSandbox. Which TWO actions can be used in an automation stitch to contain the threat?
109An NSE7 administrator is configuring a FortiGate to use the built-in intrusion prevention system (IPS) to detect and block exploits targeting a custom web application. The administrator wants to ensure that the IPS engine inspects all HTTP traffic, including encrypted sessions, without impacting performance. Which FortiGate feature should be enabled to allow IPS inspection of SSL/TLS traffic?
110A security analyst is reviewing logs from a FortiGate that uses FortiGuard IPS. The analyst notices that a signature for a recent Apache Struts vulnerability is not triggering even though the vulnerable service is exposed. The FortiGate is running the latest IPS engine and signature database. Which action should the analyst take to verify whether the signature is enabled and properly applied to the traffic?
111A FortiGate is configured with an SSL inspection profile that uses a deep-inspection mode. Users complain that a banking website fails to load, but HTTP sites work. The administrator confirms the site uses TLS 1.3 with Encrypted Client Hello (ECH) and certificate pinning. Which action should the administrator take to restore access while maintaining visibility for other traffic?
112A FortiGate is configured with a firewall policy that applies an antivirus profile with FortiSandbox inspection enabled. Users report that when they download a suspicious executable from an HTTPS website, the download completes and the file runs, but no verdict is ever returned from FortiSandbox. The administrator confirms that FortiSandbox is reachable and other protocols are being inspected successfully. Which action will most likely resolve the issue?
113A security administrator is configuring a FortiGate to use an external threat intelligence feed via a Threat Feed connector. The administrator wants to ensure that the firewall automatically blocks traffic to malicious IP addresses and domains from the feed. Which two actions are required to achieve this? (Choose two.)
114A security analyst is reviewing FortiGate logs and notices that several internal hosts are repeatedly connecting to a domain that is known to host malware. The domain is not present in any local or FortiGuard category. The analyst wants to automatically block future connections to this domain and similar malicious domains without manual intervention. Which FortiGate feature should be configured to achieve this?
115A FortiGate administrator is configuring a security profile group and wants to enable inline blocking of malicious files based on FortiGuard cloud threat intelligence, without sending files to FortiSandbox. The administrator has already enabled the antivirus profile and selected the 'Block' action for infected files. Which additional setting should be configured to ensure that files identified as malicious by the FortiGuard service are blocked in real time?
116A security administrator is configuring a FortiGate to block outbound traffic to known command-and-control (C2) servers. The administrator wants to use a dynamic, cloud-based threat intelligence service that is continuously updated by Fortinet. Which FortiGuard service should be enabled to block traffic based on the latest C2 IP addresses and domains?
117An administrator has configured FortiSandbox integration with FortiGate. Files are being submitted, but the firewall is not blocking subsequent downloads of files that FortiSandbox later identifies as malicious. The administrator verifies that the FortiSandbox license is valid and the connection is up. Which configuration is most likely missing?
118A FortiGate administrator is using the built-in FortiGuard web filter to block malicious websites. Users report that they can still access a site that is categorized as 'Malware' by FortiGuard. The administrator verifies that the web filter profile is applied to the policy and that the category is set to block. What is the most likely reason for this issue?
119A FortiGate administrator is configuring a web filter profile to block access to known malicious websites. The administrator wants to ensure that the firewall blocks sites based on FortiGuard category 'Malicious Websites' and also logs the blocked attempts. Which action should the administrator take?
120An administrator wants to use FortiGate to block outbound traffic to known malicious IP addresses based on a threat intelligence feed. They configure a threat feed connector and a firewall policy with a destination address group. However, the policy is not blocking traffic to the malicious IPs. What is the most likely cause?
121A security team is deploying FortiEDR to protect endpoints. They want to ensure that when a threat is detected, the endpoint is automatically isolated from the network to prevent lateral movement. However, they also need to allow the endpoint to communicate with the FortiEDR management server for updates and remediation. Which FortiEDR feature should they configure to achieve this?
122A FortiGate administrator is configuring SSL inspection on a policy that handles outbound HTTPS traffic. Users report that after enabling deep inspection, some business-critical applications that use certificate pinning fail. The administrator needs to inspect as much traffic as possible while keeping those pinned applications working. What should the administrator do?
123An administrator is configuring FortiGate to inspect SSL traffic for malware. They enable deep inspection in the SSL inspection profile and apply it to a firewall policy. Users report that some HTTPS websites are showing certificate errors. What is the most likely cause?
124A security analyst is reviewing FortiGate logs and notices that a known malicious file hash is being downloaded repeatedly, but the antivirus profile is not blocking it. The file is detected by FortiSandbox, and the FortiGate has a valid FortiGuard license. Which action should the analyst take to ensure the hash is blocked on subsequent downloads?
125A network administrator is deploying FortiGate to protect against unknown malware. They want to use machine learning to detect and block malicious files without relying on signatures. Which antivirus scanning technique should be enabled to achieve this?
126An administrator wants to block outbound traffic from internal hosts to known malicious domains without relying on full URL inspection or certificate inspection. The requirement is to use a lightweight DNS-based security service on FortiGate that can block botnet C2 and phishing domains. Which FortiGuard feature should the administrator enable and configure in a DNS filter profile?
127A security team uses FortiSandbox in a FortiGate security fabric. They want files that receive a 'Malicious' verdict to be automatically quarantined and their source endpoints isolated without manual intervention. Which combination of Fortinet components and features must be configured to achieve this automated response?
128A FortiGate administrator has enabled FortiGuard Outbreak Prevention and selects the 'Use Outbreak Prevention Database' option. After a new outbreak is detected, the administrator verifies that the IPS signature is applied to all applicable policies. However, the administrator wants to ensure that the FortiGate dynamically updates its protection without requiring a full IPS engine update. Which FortiGuard service must be reachable for the FortiGate to receive outbreak prevention updates?
129An administrator is configuring a FortiGate to detect and block command and control (C2) traffic using FortiGuard's Indicator of Compromise (IoC) service. The administrator wants to ensure that the firewall checks DNS queries and HTTP requests against the IoC database. Which feature should be enabled on the FortiGate to accomplish this?
130A network security administrator wants to use FortiGate to automatically quarantine an endpoint when FortiEDR detects malicious behavior on that endpoint. Which FortiGate feature should be used to integrate with FortiEDR for this purpose?
131An administrator is configuring a FortiGate to use the FortiGuard Web Filter to block access to newly registered domains that are often used in phishing campaigns. The administrator wants the block to occur with minimal impact on legitimate business traffic and without relying on manual URL submissions. Which FortiGuard Web Filter category should be used?
132A security administrator is configuring FortiGate to detect and block command-and-control (C2) traffic using the botnet database and DNS filtering. The administrator wants to ensure that infected internal hosts are identified and their C2 communication is blocked. Which two actions should the administrator take? (Choose two.)
133A security administrator is reviewing threat logs on a FortiGate running FortiOS 7.4. Multiple internal hosts have triggered IPS signatures for a known botnet C2 domain, but the administrator wants to ensure that DNS queries to this domain are blocked before a connection is attempted. The FortiGate is already using the default FortiGuard ISDB and IPS signatures. Which FortiGate feature should the administrator configure to block DNS resolution of the malicious domain?
134A security analyst is investigating alerts from FortiGate's IPS. They notice that an attack was detected but not blocked, even though the IPS profile is set to block. The log shows the action as 'detected'. What is the most likely reason for this behavior?
135A company uses FortiEDR and wants to ensure that when an endpoint is compromised, the threat is contained and the security team receives detailed forensics. The team also wants to prevent the malicious process from communicating with its command-and-control server. Which FortiEDR feature should be configured to achieve both containment and forensic data collection?
136A network security administrator notices that FortiGate is not blocking outbound traffic to domains that FortiGuard classifies as malicious. The administrator confirms that the license is valid and FortiGuard category-based blocking is enabled. Which FortiGate feature should be verified to ensure that DNS queries for malicious domains are intercepted and sinkholed?
137A FortiGate administrator wants to stop outbound DNS queries to a known malicious domain that is not present in any static blocklist. The administrator has already licensed FortiGuard DNS Filtering and enabled DNS filtering on the firewall policy. Which FortiGuard service must the FortiGate resolve the domain against so that the query is blocked based on the latest threat intelligence?
138A security analyst is investigating a recent security incident and wants to use FortiGate's Security Fabric to gather threat intelligence. The analyst needs to view detailed information about a detected threat, including the source, destination, and the specific IPS signature that triggered. Which FortiGate feature provides a centralized view of threat events and allows drill-down into individual incidents?
139A network security administrator is deploying a FortiSandbox appliance in a FortiGate environment. The administrator wants to ensure that when a zero-day malware sample is detonated, the FortiGate immediately blocks the file hash and the C2 callback. Which FortiSandbox integration method should the administrator configure on the FortiGate to achieve this?
140An administrator is configuring a FortiGate to block outbound traffic to known malicious IP addresses. They want the block list to be updated automatically from a commercial threat intelligence service that provides a REST API. Which FortiGate feature should be used?
141A network administrator is configuring a FortiGate to protect against unknown malware by using machine learning. The administrator wants to enable the feature that uses machine learning to detect and block malicious files based on their behavior and characteristics, without relying solely on signatures. Which antivirus setting should the administrator enable?
142A security administrator is deploying FortiDeceptor in a data center network. They want to detect an attacker who is performing internal reconnaissance by scanning the subnet for live hosts. Which FortiDeceptor component should the administrator deploy to generate a decoy IP address that responds to such scans and alerts on any interaction?
143A FortiGate administrator is configuring a security profile to detect command-and-control traffic from internal hosts. The administrator wants to use a signature-based detection method that matches known botnet patterns. Which FortiGate feature should be enabled to accomplish this?
144A security administrator is configuring a FortiGate to use an external threat intelligence feed to block malicious IP addresses. The administrator wants the FortiGate to automatically update the list of malicious IPs from a threat feed and use it in firewall policies. Which FortiGate feature should be used?
145A security analyst is reviewing FortiGate logs and notices that a web filter profile is blocking access to a known malicious domain, but the block page shows the category as 'Unrated'. The analyst confirms the domain is listed in a custom blocklist. Which FortiGate feature is responsible for overriding the category and enforcing the block?
146A FortiGate running FortiOS 7.4 is configured with a firewall policy that references an IPS sensor. The sensor uses a custom signature to detect a recently discovered exploit. Users report that the exploit traffic is not being blocked even though the signature is enabled. The administrator confirms the traffic matches the signature and that the policy is in flow-based inspection mode. Which action should the administrator take to ensure the IPS sensor can block the exploit?
147A security analyst is investigating an alert from FortiSandbox indicating that a file has a high-risk verdict. The analyst wants to automatically prevent the file from executing on other endpoints. Which FortiSandbox integration should be configured to achieve this?
148A security administrator is configuring a FortiGate to use a threat feed connector to block traffic from known malicious IP addresses. The administrator wants to ensure that the threat feed is updated automatically and that the FortiGate can use the feed in firewall policies. Which two actions must the administrator perform? (Choose two.)
149A FortiGate administrator is configuring a firewall policy to inspect traffic for advanced threats. The administrator wants to ensure that the policy uses both antivirus and IPS inspection, and that the traffic is inspected in a way that minimizes latency while still detecting threats. Which two actions should the administrator take? (Choose two.)
150A FortiGate administrator wants to prevent users from accessing a list of known malicious domains. The list is updated daily by a third-party provider and available as a plain text file over HTTPS. Which FortiGate feature should be used to ingest and block these domains?
151A FortiGate administrator has configured a firewall policy with a web filter profile that uses a FortiGuard category action to block 'Malware' websites. Users report that they can still access some known malicious sites that are categorized as 'Malware'. The administrator verifies that the FortiGuard service is reachable and the license is valid. What is the most likely cause?
152A security analyst is reviewing alerts from FortiEDR and wants to automatically isolate an infected endpoint from the network when a malicious process is detected. Which FortiEDR feature should the analyst configure to achieve this?
153An administrator is configuring a FortiGate to detect and block traffic to known malicious domains using DNS filtering. The administrator wants to ensure that DNS queries for malicious domains are blocked and that users are redirected to a block page. Which DNS filter action should be configured?
154An administrator is configuring a FortiGate to use the external threat feed feature to block traffic from known malicious IP addresses. They want to ensure that the feed is automatically updated and that the firewall blocks traffic based on the feed. Which two actions must the administrator perform? (Choose two.)
155A FortiGate administrator is configuring an antivirus profile to protect against unknown malware. The administrator wants to use machine learning to detect malicious files based on their behavior and characteristics without relying solely on signatures. Which antivirus feature should be enabled to meet this requirement?
156A security team is using FortiSandbox to analyze suspicious files. They notice that some files are being analyzed but the verdicts are not being sent back to the FortiGate, so the firewall is not blocking them. Which FortiSandbox setting should the administrator verify to ensure verdicts are returned to the FortiGate?
157A FortiGate administrator has configured an antivirus profile with sandbox inspection and applied it to a firewall policy. Users report that downloads of executable files are delayed significantly, but eventually complete. The administrator wants to reduce the delay while still blocking malicious files before they reach the endpoint. Which change should the administrator make?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to map a threat scenario to the right Fortinet components: IPS sensor plus automation stitch for auto-blocking, FortiSIEM or FortiAnalyzer for correlation, FortiEDR for endpoint containment. The key is pairing the correct trigger with the correct response action.
The Courseiva NSE7 question bank contains 157 questions in the Advanced Threat Protection domain, covering the 20% of the exam attributed to this domain in the official Fortinet blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Advanced Threat Protection domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included