Courseiva

NSE7 Advanced Threat Protection Practice Question

A FortiGate administrator is configuring an antivirus profile to protect against unknown malware. The administrator wants to use machine learning to detect malicious files based on their behavior and characteristics without relying solely on signatures. Which antivirus feature should be enabled to meet this requirement?

⚠ Common exam trap

The trap here is equating sandbox inspection or CDR with machine learning, when the antivirus profile has a distinct ML detection setting that must be enabled for behavior-based unknown malware detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Machine Learning (ML) malware detection

FortiGate antivirus profiles offer a machine learning detection option that uses models to classify files as malicious based on their characteristics and behavior. This provides protection against unknown malware without waiting for signatures. Signature-only detection, sandbox inspection, and CDR serve different purposes and do not meet the specific requirement for ML-based detection on the firewall.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Machine Learning (ML) malware detection

    Why this is correct

    FortiGate antivirus profiles include a machine learning option that uses trained models to identify malicious files based on file features and behavior, not just signatures. Enabling ML detection allows the firewall to catch unknown malware that has no signature. This directly addresses the requirement to detect unknown threats without relying solely on signature updates.

  • ✗

    Content disarm and reconstruction (CDR)

    Why it's wrong here

    CDR removes potentially malicious content from files and reconstructs them, which can neutralize threats but is not a machine learning detection method. It does not analyze file behavior to classify malware. The requirement is for ML-based detection, so CDR does not satisfy the scenario even though it can help against unknown threats in some cases.

  • ✗

    FortiGuard Antivirus signatures

    Why it's wrong here

    FortiGuard antivirus signatures are traditional pattern-based detections for known malware. They do not provide machine learning-based detection of unknown or zero-day malware. Relying only on signatures means new threats without an existing signature will be missed. The administrator specifically wants behavior and characteristic-based detection, which signatures alone cannot deliver.

  • ✗

    Sandbox inspection

    Why it's wrong here

    Sandbox inspection sends suspicious files to FortiSandbox for dynamic analysis, which is effective for unknown malware but requires an external appliance and is not a machine learning feature on the FortiGate itself. The administrator asked for machine learning within the antivirus profile. While sandboxing complements ML, it is not the ML detection feature and may introduce latency.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.