NSE7 Advanced Threat Protection Practice Question
A FortiGate administrator is configuring a security profile to detect command-and-control traffic from internal hosts. The administrator wants to use a signature-based detection method that matches known botnet patterns. Which FortiGate feature should be enabled to accomplish this?
⚠ Common exam trap
The trap here is assuming that application control or DNS filtering can substitute for IPS when detecting botnet command-and-control traffic, but only IPS provides the deep packet inspection with botnet-specific signatures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Intrusion Prevention System (IPS) with botnet signatures
The Intrusion Prevention System (IPS) on FortiGate uses a signature database that includes patterns for known botnet command-and-control traffic. Enabling IPS with botnet signatures allows the firewall to inspect packets and block or log C2 communications. Other features like web filtering, application control, or DNS filtering do not provide the same level of signature-based detection for C2 traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Intrusion Prevention System (IPS) with botnet signatures
Why this is correct
The IPS engine on FortiGate includes a comprehensive signature database that detects known botnet command-and-control patterns. When enabled, IPS inspects traffic flows and matches them against signatures specifically designed to identify C2 communication, such as those used by Mirai or Necurs. This provides the required signature-based detection and can block or log the traffic, directly addressing the administrator's goal.
- ✗
Application Control with botnet category
Why it's wrong here
Application Control identifies applications based on behavior and protocol, not specific malicious signatures. While it can block applications categorized as 'Botnet', this relies on application signatures rather than the detailed pattern matching of IPS. It may miss custom or encrypted C2 channels that IPS signatures would detect. Thus, it does not fully satisfy the requirement for signature-based botnet detection.
- ✗
DNS Filter with botnet domain database
Why it's wrong here
DNS Filter blocks DNS queries to known malicious domains, which can disrupt C2 if the botnet uses domain names. However, it does not inspect the actual traffic for botnet signatures and is ineffective against C2 that uses direct IP addresses or domain generation algorithms. The administrator specifically asked for signature-based detection of C2 traffic, which DNS Filter does not provide.
- ✗
FortiGuard Category Based Filter
Why it's wrong here
FortiGuard Category Based Filter is used within web filtering to block or allow websites based on their category, such as 'Malware' or 'Phishing'. It does not inspect network traffic for botnet command-and-control signatures. This feature operates at the application layer for HTTP/HTTPS traffic and lacks the packet-level pattern matching required for C2 detection. Therefore, it is not suitable for this scenario.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.