Courseiva

NSE7 Advanced Threat Protection Practice Question

A company uses FortiEDR and wants to ensure that when an endpoint is compromised, the threat is contained and the security team receives detailed forensics. The team also wants to prevent the malicious process from communicating with its command-and-control server. Which FortiEDR feature should be configured to achieve both containment and forensic data collection?

⚠ Common exam trap

The trap here is equating monitoring or logging features with automated containment, when only a playbook action can block, remediate, and collect forensics in one triggered workflow.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use 'Playbooks' with a 'Block and Remediate' action triggered by a malicious verdict.

FortiEDR playbooks automate responses based on verdicts. A Block and Remediate playbook can terminate the malicious process, sever command-and-control communication, and initiate forensic collection. Logging, exclusions, or monitoring alone do not provide containment, so they cannot meet the combined requirement for automated containment and detailed forensics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable 'Security Events' with 'Log' action for all process executions.

    Why it's wrong here

    Security Events with a Log action record process execution details but do not block or contain malicious activity. Logging alone would allow the malicious process to continue communicating with its command-and-control server, failing the containment requirement. It also does not automatically collect the deep forensic artefacts needed for incident response.

  • ✗

    Set the 'Threat Hunting' module to 'Monitor' mode for all endpoints.

    Why it's wrong here

    Threat Hunting in monitor mode provides visibility and investigation capabilities but does not automatically contain threats or block command-and-control traffic. It is designed for proactive hunting rather than automated response, so it would leave the malicious process running and would not collect the targeted forensic artefacts required for this incident.

  • ✗

    Configure 'Exclusions' to prevent FortiEDR from scanning critical applications.

    Why it's wrong here

    Exclusions are used to reduce false positives by skipping known-good applications. They do not provide containment or forensic collection, and if applied to a compromised application they would actively prevent detection. This option moves in the opposite direction of the scenario's goal of containing and investigating a threat.

  • ✓

    Use 'Playbooks' with a 'Block and Remediate' action triggered by a malicious verdict.

    Why this is correct

    FortiEDR playbooks can automatically execute block and remediate actions when a malicious verdict is reached. This stops the malicious process, prevents command-and-control communication, and triggers collection of forensic data such as memory dumps and process trees. It directly satisfies both the containment and the forensic requirements described in the scenario.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.