Courseiva
Advanced Threat ProtectionmediumMultiple SelectObjective-mapped

Custom IPS Signature Options for Protocol Anomaly Detection on FortiGate

A FortiGate administrator wants to detect and block protocol anomalies as part of advanced IPS. Which three options are available in FortiGate's custom IPS signatures? (Choose three.)

Quick Answer

The correct answers are packet length constraints, protocol field matching, and protocol anomaly detection. Custom IPS signatures on FortiGate allow administrators to define precise detection criteria by targeting specific protocol fields, enforcing packet length constraints, and identifying protocol anomalies that deviate from RFC standards, all of which are essential for blocking non-standard traffic without relying on pre-defined signatures. On the Fortinet NSE 7 Advanced Security NSE7 exam, this question tests your understanding of the three distinct options available within the custom IPS signature engine, often tripping candidates who mistakenly select application control—a separate feature that operates at a different layer. A common trap is confusing protocol anomaly detection with application control, but remember: custom IPS focuses on low-level protocol behavior, not application identification. Memory tip: think “Fields, Length, Anomaly” as the three pillars of custom IPS signatures.

⚠ Common exam trap

Many exam-takers confuse application control signatures (which identify applications by traffic patterns) with IPS protocol anomaly signatures, or mistakenly think URL filtering is part of IPS when it is a separate security profile feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Protocol-specific fields

Custom IPS signatures in FortiGate allow matching on protocol-specific fields such as TCP flags, ICMP type/code, or DNS query types. This enables detection of anomalies like invalid flag combinations or malformed protocol headers, which is a core part of advanced IPS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Protocol-specific fields

    Why this is correct

    Can specify fields like TCP flags, HTTP headers.

  • Protocol anomaly detection

    Why this is correct

    Custom signatures can detect anomalies like invalid protocol combinations.

  • Packet length constraints

    Why this is correct

    Can detect packets with abnormal lengths.

  • Application signatures

    Why it's wrong here

    Application signatures are part of application control, not custom IPS signatures.

  • URL filtering

    Why it's wrong here

    URL filtering is separate from IPS.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE7

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A FortiGate administrator wants to block a custom protocol anomaly where a client sends an HTTP request with a malformed header containing a null byte. Which advanced IPS feature should be used?

hard
  • A.Create a custom IPS signature to match the null byte pattern
  • B.Enable 'Outbreak Prevention' in the IPS sensor
  • C.Use the 'http-policy' setting in the WAF profile
  • D.Enable Protocol Anomaly Detection in the IPS sensor

Why D: Protocol Anomaly Detection in the IPS sensor is designed to identify deviations from standard protocol behavior, such as malformed headers or null bytes in HTTP requests. This feature inspects traffic for known protocol violations without requiring custom signatures, making it the correct choice for blocking a null byte anomaly in HTTP headers.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.