Courseiva
Advanced Threat Protection →mediumMultiple Choice

NSE7 Advanced Threat Protection Practice Question

A FortiGate administrator has configured a firewall policy with a web filter profile that uses a FortiGuard category action to block 'Malware' websites. Users report that they can still access some known malicious sites that are categorized as 'Malware'. The administrator verifies that the FortiGuard service is reachable and the license is valid. What is the most likely cause?

⚠ Common exam trap

The trap here is overlooking the category action setting and assuming a connectivity or inspection mode issue when the action is simply set to Monitor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The 'Malware' category is set to 'Monitor' instead of 'Block' in the web filter profile.

The FortiGuard category action for 'Malware' must be set to Block to prevent access to sites in that category. If it is set to Monitor, the sites are allowed and only logged. Since the administrator confirmed FortiGuard connectivity and licensing, the most likely cause is that the category action is not set to Block.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The 'Malware' category is set to 'Monitor' instead of 'Block' in the web filter profile.

    Why this is correct

    If the FortiGuard category action for 'Malware' is set to Monitor, traffic to those sites is allowed but logged. This would explain why some known malicious sites are accessible despite the administrator's intention to block them. The category action must be explicitly set to Block to enforce blocking, making this the most likely cause.

  • ✗

    The FortiGate is using flow-based inspection, which does not support category-based blocking.

    Why it's wrong here

    Flow-based inspection does support category-based blocking; the inspection mode affects how content is scanned, not whether categories can be blocked. Both flow-based and proxy-based modes can enforce web filter category actions. Therefore, this is not a valid reason for the failure.

  • ✗

    The static URL filter is allowing the malicious sites before the category action is evaluated.

    Why it's wrong here

    Static URL filter entries are evaluated before category actions, but if a static entry were allowing the sites, it would have to be explicitly configured to allow. The scenario does not mention any static allow entries, and the default behavior is to continue to category evaluation. This is less likely than a misconfigured category action.

  • ✗

    The web filter profile is not applied to the correct firewall policy or traffic direction.

    Why it's wrong here

    If the web filter profile were not applied, no category blocking would occur at all, and users would likely be able to access all sites. The fact that some sites are blocked indicates the profile is active. However, it is possible that the profile is applied only to certain policies, but the scenario states that some malicious sites are accessible, suggesting a more specific issue.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.