NSE7 Advanced Threat Protection Practice Question
A company uses FortiGate as a web application firewall (WAF) to protect a public web server. The security team wants to block SQL injection attacks. Which WAF signature category should the administrator enable?
⚠ Common exam trap
Candidates often confuse SQL Injection with Command Injection (Option B) because both involve injection attacks, but SQL Injection targets database layers via SQL syntax, while Command Injection targets the OS shell via system commands.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SQL Injection
SQL injection attacks specifically target database queries by injecting malicious SQL statements through input fields. FortiGate's WAF signature category for SQL Injection is designed to detect and block these patterns, such as 'OR 1=1' or UNION-based injections, by matching against known attack signatures in the HTTP request payload.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Server-Side Request Forgery
Why it's wrong here
Server-Side Request Forgery signatures target forged server-side requests, not SQL injection syntax, so enabling this category leaves injection attempts unmatched. It is tempting because SSRF is also a web attack category, and it would be correct when the requirement is blocking requests that trick the server into fetching internal resources.
- ✗
Command Injection
Why it's wrong here
Command Injection signatures match shell and OS command metacharacters passed to system calls, not SQL syntax. It tempts because injection flaws share the same untrusted-input root cause, and this category is the right pick when the target is an operating-system command interpreter rather than a database query parser.
- ✓
SQL Injection
Why this is correct
The SQL Injection signature category contains patterns matching SQL syntax manipulation in HTTP requests. Enabling it lets the WAF inspect parameters and block injection attempts, directly satisfying the requirement to block SQL injection attacks against the public web server.
- ✗
Cross-Site Scripting
Why it's wrong here
Cross-Site Scripting signatures match reflected or stored script payloads executed in a victim's browser, so they never inspect SQL grammar. It tempts because XSS is the other headline web-injection class, and this category would be correct when the protected application echoes attacker-controlled JavaScript back to users.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.