Courseiva
Advanced Threat Protection →mediumMultiple Choice

NSE7 Advanced Threat Protection Practice Question

A FortiGate administrator is configuring a web filter profile to block access to known malicious websites. The administrator wants to ensure that the firewall blocks sites based on FortiGuard category 'Malicious Websites' and also logs the blocked attempts. Which action should the administrator take?

⚠ Common exam trap

A common mix-up: candidates confuse DNS filter with web filter for category-based blocking, or thinking antivirus handles URL blocking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a web filter profile with the 'Malicious Websites' category set to 'Block' and apply it to a firewall policy with logging enabled.

Using a web filter profile with the 'Malicious Websites' category set to block, applied to a firewall policy with logging, ensures both blocking and logging of attempts. DNS filter is not the right profile for this category, antivirus does not handle URL blocking, and static address objects cannot replace dynamic FortiGuard categories.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a web filter profile with the 'Malicious Websites' category set to 'Block' and apply it to a firewall policy with logging enabled.

    Why this is correct

    Setting the 'Malicious Websites' category to 'Block' in the web filter profile will block those sites. Applying it to a firewall policy enables enforcement. Enabling logging on the policy or profile ensures blocked attempts are recorded. This directly fulfills both requirements.

  • ✗

    Enable 'Block malicious URLs' in the antivirus profile and apply it to the firewall policy.

    Why it's wrong here

    The antivirus profile does not have a 'Block malicious URLs' option; URL blocking is handled by web filter or DNS filter. Antivirus is for file-based threats. This option is incorrect because it misattributes the feature to the wrong security profile.

  • ✗

    Create a firewall address object for the malicious websites and add it to a deny policy.

    Why it's wrong here

    Manually creating address objects for malicious websites is impractical and does not use FortiGuard categories. The requirement is to block based on the FortiGuard 'Malicious Websites' category, which is dynamic and updated by FortiGuard. A static address object would not keep up with new malicious sites.

  • ✗

    Create a DNS filter profile with the 'Malicious Websites' category set to 'Block' and apply it to a firewall policy.

    Why it's wrong here

    DNS filter profiles block based on domain categories, but the 'Malicious Websites' category is primarily a web filter category. While DNS filtering can block domains, it does not provide the same granularity and may not use the same category. The question specifies web filter profile, so this is not the correct approach.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.