Courseiva

NSE7 Advanced Threat Protection Practice Question

A company is deploying FortiGate with Advanced Threat Protection (ATP) and wants to block advanced malware that uses encrypted C2 communications. Which security profile should be configured to perform SSL inspection and detect malicious traffic?

⚠ Common exam trap

Watch out — candidates often assume IPS or Web Filtering alone can block encrypted C2 traffic, but without SSL inspection, these profiles cannot see inside the encrypted tunnel, making the Antivirus profile with SSL inspection the only correct choice for detecting malware in encrypted communications.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Antivirus profile with SSL inspection

An Antivirus profile with SSL inspection enabled is required to decrypt encrypted C2 (command-and-control) traffic so that FortiGate can inspect the payload for malware signatures, heuristics, and behavioral patterns. Without SSL inspection, the ATP engine cannot see inside the encrypted tunnel, rendering the antivirus and other security profiles ineffective against encrypted C2 communications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data Leak Prevention profile

    Why it's wrong here

    DLP inspects content for sensitive data patterns such as credit card numbers or personal records, not encrypted command-and-control traffic. It cannot decrypt TLS or match malware signatures. DLP would be the correct profile when the requirement is preventing exfiltration of confidential information, not blocking ATP-detected C2 channels.

  • ✓

    Antivirus profile with SSL inspection

    Why this is correct

    The antivirus profile, when combined with SSL inspection, decrypts TLS sessions so the malware signatures and CDR engines can examine payloads hidden inside encrypted channels. This satisfies the requirement to block advanced malware using encrypted command-and-control traffic.

  • ✗

    Web Filtering profile

    Why it's wrong here

    Web Filtering categorises URLs and blocks access by reputation or category, but it does not decrypt TLS sessions or inspect payloads for malware signatures. SSL inspection with ATP detection is performed by the antivirus profile. Web Filtering would be correct when the goal is enforcing acceptable-use policy on web destinations.

  • ✗

    Intrusion Prevention profile

    Why it's wrong here

    The Intrusion Prevention profile inspects traffic signatures but does not decrypt TLS, so encrypted command-and-control channels remain opaque. It is tempting because IPS blocks known malicious patterns, which is correct for cleartext attacks, whereas SSL inspection requires the deep-inspection or certificate-inspection profile.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.