NSE7 Advanced Threat Protection Practice Question
A company is deploying FortiGate with Advanced Threat Protection (ATP) and wants to block advanced malware that uses encrypted C2 communications. Which security profile should be configured to perform SSL inspection and detect malicious traffic?
⚠ Common exam trap
Watch out — candidates often assume IPS or Web Filtering alone can block encrypted C2 traffic, but without SSL inspection, these profiles cannot see inside the encrypted tunnel, making the Antivirus profile with SSL inspection the only correct choice for detecting malware in encrypted communications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Antivirus profile with SSL inspection
An Antivirus profile with SSL inspection enabled is required to decrypt encrypted C2 (command-and-control) traffic so that FortiGate can inspect the payload for malware signatures, heuristics, and behavioral patterns. Without SSL inspection, the ATP engine cannot see inside the encrypted tunnel, rendering the antivirus and other security profiles ineffective against encrypted C2 communications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data Leak Prevention profile
Why it's wrong here
DLP inspects content for sensitive data patterns such as credit card numbers or personal records, not encrypted command-and-control traffic. It cannot decrypt TLS or match malware signatures. DLP would be the correct profile when the requirement is preventing exfiltration of confidential information, not blocking ATP-detected C2 channels.
- ✓
Antivirus profile with SSL inspection
Why this is correct
The antivirus profile, when combined with SSL inspection, decrypts TLS sessions so the malware signatures and CDR engines can examine payloads hidden inside encrypted channels. This satisfies the requirement to block advanced malware using encrypted command-and-control traffic.
- ✗
Web Filtering profile
Why it's wrong here
Web Filtering categorises URLs and blocks access by reputation or category, but it does not decrypt TLS sessions or inspect payloads for malware signatures. SSL inspection with ATP detection is performed by the antivirus profile. Web Filtering would be correct when the goal is enforcing acceptable-use policy on web destinations.
- ✗
Intrusion Prevention profile
Why it's wrong here
The Intrusion Prevention profile inspects traffic signatures but does not decrypt TLS, so encrypted command-and-control channels remain opaque. It is tempting because IPS blocks known malicious patterns, which is correct for cleartext attacks, whereas SSL inspection requires the deep-inspection or certificate-inspection profile.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.