Custom IPS Signature Options for Protocol Anomaly Detection on FortiGate
A FortiGate administrator wants to detect and block protocol anomalies as part of advanced IPS. Which three options are available in FortiGate's custom IPS signatures? (Choose three.)
Quick Answer
The correct answers are packet length constraints, protocol field matching, and protocol anomaly detection. Custom IPS signatures on FortiGate allow administrators to define precise detection criteria by targeting specific protocol fields, enforcing packet length constraints, and identifying protocol anomalies that deviate from RFC standards, all of which are essential for blocking non-standard traffic without relying on pre-defined signatures. On the Fortinet NSE 7 Advanced Security NSE7 exam, this question tests your understanding of the three distinct options available within the custom IPS signature engine, often tripping candidates who mistakenly select application control—a separate feature that operates at a different layer. A common trap is confusing protocol anomaly detection with application control, but remember: custom IPS focuses on low-level protocol behavior, not application identification. Memory tip: think “Fields, Length, Anomaly” as the three pillars of custom IPS signatures.
⚠ Common exam trap
Many exam-takers confuse application control signatures (which identify applications by traffic patterns) with IPS protocol anomaly signatures, or mistakenly think URL filtering is part of IPS when it is a separate security profile feature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Protocol-specific fields
Custom IPS signatures in FortiGate allow matching on protocol-specific fields such as TCP flags, ICMP type/code, or DNS query types. This enables detection of anomalies like invalid flag combinations or malformed protocol headers, which is a core part of advanced IPS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Protocol-specific fields
Why this is correct
Can specify fields like TCP flags, HTTP headers.
- ✓
Protocol anomaly detection
Why this is correct
Custom signatures can detect anomalies like invalid protocol combinations.
- ✓
Packet length constraints
Why this is correct
Can detect packets with abnormal lengths.
- ✗
Application signatures
Why it's wrong here
Application signatures are part of application control, not custom IPS signatures.
- ✗
URL filtering
Why it's wrong here
URL filtering is separate from IPS.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE7
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A FortiGate administrator wants to block a custom protocol anomaly where a client sends an HTTP request with a malformed header containing a null byte. Which advanced IPS feature should be used?
hard- A.Create a custom IPS signature to match the null byte pattern
- B.Enable 'Outbreak Prevention' in the IPS sensor
- C.Use the 'http-policy' setting in the WAF profile
- ✓ D.Enable Protocol Anomaly Detection in the IPS sensor
Why D: Protocol Anomaly Detection in the IPS sensor is designed to identify deviations from standard protocol behavior, such as malformed headers or null bytes in HTTP requests. This feature inspects traffic for known protocol violations without requiring custom signatures, making it the correct choice for blocking a null byte anomaly in HTTP headers.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.