NSE7 Advanced Threat Protection Practice Question
A FortiGate administrator wants to stop outbound DNS queries to a known malicious domain that is not present in any static blocklist. The administrator has already licensed FortiGuard DNS Filtering and enabled DNS filtering on the firewall policy. Which FortiGuard service must the FortiGate resolve the domain against so that the query is blocked based on the latest threat intelligence?
⚠ Common exam trap
The trap here is assuming that any FortiGuard security service enabled on a policy will automatically inspect DNS queries, when only the DNS Filtering service is queried for domain reputation during resolution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FortiGuard DNS Filtering service
FortiGuard DNS Filtering is the service that evaluates domain names during DNS resolution and blocks queries for malicious or risky domains. Enabling DNS filtering on the firewall policy causes the FortiGate to consult this service for each lookup, so the endpoint never receives the IP address. Web Filtering, Antispam, and IP Reputation operate at different layers and cannot stop the domain from resolving.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
FortiGuard IP Reputation service
Why it's wrong here
IP Reputation rates source and destination IP addresses for traffic sessions, but it does not evaluate the domain name being resolved. At the moment of the DNS query the endpoint has not yet learned the IP address, so an IP reputation lookup cannot block the resolution. The malicious domain would resolve successfully before any IP-based policy could act.
- ✗
FortiGuard Antispam service
Why it's wrong here
The Antispam service checks email sender reputation and message characteristics for SMTP traffic, not DNS queries. It cannot rate a domain that is being resolved by an internal host. Enabling DNS filtering on the policy does not route lookups through the antispam database, so a malicious domain would still resolve and the endpoint could connect to it.
- ✓
FortiGuard DNS Filtering service
Why this is correct
The FortiGuard DNS Filtering service maintains a real-time database of malicious and risky domains specifically for DNS resolution requests. When DNS filtering is enabled on the policy, the FortiGate sends the queried domain to this service and blocks the response if the domain is rated as malicious. This directly prevents the endpoint from learning the IP address of the malicious domain.
- ✗
FortiGuard Web Filtering
Why it's wrong here
Web Filtering categorizes HTTP and HTTPS destinations for web access policies, but DNS filtering does not consult the web category database to block a domain lookup. In this scenario the administrator needs a DNS-specific reputation lookup, not an HTTP category lookup. Web Filtering would not stop the DNS query before resolution occurs, so the outbound query to the malicious domain would still succeed.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.