Courseiva
Advanced Threat ProtectionhardMultiple ChoiceObjective-mapped

NSE7 Advanced Threat Protection Practice Question

A FortiGate administrator runs the following CLI command: 'diagnose ips anomaly log' The output shows numerous 'tcp_syn_flood' events from a single source IP. To mitigate this, the administrator wants to block the source IP automatically. Which feature should be used?

⚠ Common exam trap

Candidates often confuse the IP Block List (a static or manually managed list) with the Automation Stitch (the automated engine that can dynamically add entries to that list based on events), leading them to select Option C instead of D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Automation Stitch

The 'diagnose ips anomaly log' command displays anomalies detected by the FortiGate's DoS (Denial of Service) sensor, such as TCP SYN flood events. An Automation Stitch (Option D) is the correct feature to automatically block the source IP because it can trigger a 'Block IP' action based on a 'IPS Anomaly' event, creating an automated response without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • IPS Custom Signature

    Why it's wrong here

    Custom signatures detect but do not automatically block by adding to block list.

  • Local-in Policy

    Why it's wrong here

    Local-in policy controls traffic to FortiGate itself, not automatic blocking.

  • IP Block List

    Why it's wrong here

    IP Block List is static; automatic blocking requires a dynamic response.

  • Automation Stitch

    Why this is correct

    Automation stitches can automate responses to events like syn flood.

About these practice questions

This NSE7 question is part of Courseiva's 940-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.