NSE7 Advanced Threat Protection Practice Question
A FortiGate administrator is configuring a firewall policy to inspect traffic for advanced threats. The administrator wants to ensure that the policy uses both antivirus and IPS inspection, and that the traffic is inspected in a way that minimizes latency while still detecting threats. Which two actions should the administrator take? (Choose two.)
⚠ Common exam trap
The trap here is assuming that any inspection mode works equally well for low latency, or that adding more security profiles like sandboxing automatically improves performance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply an antivirus profile and an IPS sensor to the firewall policy.
To minimize latency while inspecting for advanced threats, flow-based inspection should be used because it processes packets without full buffering. Additionally, both an antivirus profile and an IPS sensor must be applied to the firewall policy to ensure that malware and network attacks are detected. These two actions together satisfy the performance and security requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable 'Scan with FortiSandbox' in the antivirus profile.
Why it's wrong here
Enabling FortiSandbox scanning adds an additional layer of analysis but does not directly address the need to minimize latency. In fact, sandbox submission can introduce delays if the policy is configured to hold files until a verdict is received. It is not one of the two actions specifically required to achieve low-latency inspection with antivirus and IPS.
- ✗
Enable 'Block Oversized Files' in the antivirus profile.
Why it's wrong here
Blocking oversized files does not contribute to minimizing latency or to enabling both antivirus and IPS inspection. It simply blocks files that exceed the oversize limit, which could disrupt legitimate traffic. This setting is unrelated to the performance and inspection mode requirements described.
- ✓
Apply an antivirus profile and an IPS sensor to the firewall policy.
Why this is correct
To inspect for advanced threats, both antivirus and IPS profiles must be attached to the firewall policy. The antivirus profile scans for malware, while the IPS sensor detects network-level attacks and exploits. Applying both ensures comprehensive threat protection as required, making this a correct action.
- ✓
Enable flow-based inspection on the firewall policy.
Why this is correct
Flow-based inspection processes packets as they arrive without buffering the entire file, which reduces latency compared to proxy-based inspection. It is suitable for real-time traffic and still applies antivirus and IPS engines. This meets the requirement to minimize latency while maintaining threat detection, making it a correct choice for the scenario.
- ✗
Enable proxy-based inspection on the firewall policy.
Why it's wrong here
Proxy-based inspection buffers content and can introduce additional latency, which contradicts the goal of minimizing latency. While it may provide more thorough inspection for certain protocols, it is not the optimal choice when low latency is a priority. Therefore, it is not one of the recommended actions for this scenario.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.