Courseiva
Advanced Threat ProtectionhardMultiple ChoiceObjective-mapped

NSE7 Advanced Threat Protection Practice Question

A FortiGate admin runs 'diagnose ips anomaly list' and sees many 'tcp_src_session' events from a single internal IP. The admin suspects a scanning attack. What action should be taken to block this traffic without affecting legitimate traffic?

⚠ Common exam trap

Test-takers frequently confuse anomaly-based detection (which triggers on aggregate session counts) with signature-based detection (which matches specific packet patterns), leading them to choose Option C, not realizing that blocking the anomaly would indiscriminately drop all traffic from the source IP, including legitimate sessions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a custom IPS signature to detect and block the scanning pattern

Creating a custom IPS signature allows you to define specific patterns (e.g., multiple TCP SYN packets to different ports from the same source) that match scanning behavior, and then set the action to 'block'. This granular approach blocks only the malicious scanning traffic while permitting legitimate traffic from the same IP, unlike a blanket IP block or a global anomaly action that could impact normal sessions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a firewall rule to block the IP address entirely

    Why it's wrong here

    Blocking the entire IP may affect legitimate services.

  • Create a custom IPS signature to detect and block the scanning pattern

    Why this is correct

    A custom signature can precisely target the scan behavior.

  • Enable 'tcp_src_session' anomaly action to 'block' in the IPS sensor

    Why it's wrong here

    This blocks the anomaly but may also impact legitimate users if thresholds are too low.

  • Use a WAF profile to block the IP based on rate

    Why it's wrong here

    WAF is for web traffic, not general TCP anomalies.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.