Courseiva
Advanced Threat Protection →mediumMultiple Choice

NSE7 Advanced Threat Protection Practice Question

A FortiGate administrator is configuring a security profile to detect command-and-control traffic from internal hosts. The administrator wants to use a signature-based detection method that matches known botnet patterns. Which FortiGate feature should be enabled to accomplish this?

⚠ Common exam trap

The trap here is assuming that application control or DNS filtering can substitute for IPS when detecting botnet command-and-control traffic, but only IPS provides the deep packet inspection with botnet-specific signatures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Intrusion Prevention System (IPS) with botnet signatures

The Intrusion Prevention System (IPS) on FortiGate uses a signature database that includes patterns for known botnet command-and-control traffic. Enabling IPS with botnet signatures allows the firewall to inspect packets and block or log C2 communications. Other features like web filtering, application control, or DNS filtering do not provide the same level of signature-based detection for C2 traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Intrusion Prevention System (IPS) with botnet signatures

    Why this is correct

    The IPS engine on FortiGate includes a comprehensive signature database that detects known botnet command-and-control patterns. When enabled, IPS inspects traffic flows and matches them against signatures specifically designed to identify C2 communication, such as those used by Mirai or Necurs. This provides the required signature-based detection and can block or log the traffic, directly addressing the administrator's goal.

  • ✗

    Application Control with botnet category

    Why it's wrong here

    Application Control identifies applications based on behavior and protocol, not specific malicious signatures. While it can block applications categorized as 'Botnet', this relies on application signatures rather than the detailed pattern matching of IPS. It may miss custom or encrypted C2 channels that IPS signatures would detect. Thus, it does not fully satisfy the requirement for signature-based botnet detection.

  • ✗

    DNS Filter with botnet domain database

    Why it's wrong here

    DNS Filter blocks DNS queries to known malicious domains, which can disrupt C2 if the botnet uses domain names. However, it does not inspect the actual traffic for botnet signatures and is ineffective against C2 that uses direct IP addresses or domain generation algorithms. The administrator specifically asked for signature-based detection of C2 traffic, which DNS Filter does not provide.

  • ✗

    FortiGuard Category Based Filter

    Why it's wrong here

    FortiGuard Category Based Filter is used within web filtering to block or allow websites based on their category, such as 'Malware' or 'Phishing'. It does not inspect network traffic for botnet command-and-control signatures. This feature operates at the application layer for HTTP/HTTPS traffic and lacks the packet-level pattern matching required for C2 detection. Therefore, it is not suitable for this scenario.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.