Courseiva

NSE7 Advanced Threat Protection Practice Question

A FortiGate is configured with a firewall policy that applies an antivirus profile with FortiSandbox inspection enabled. Users report that when they download a suspicious executable from an HTTPS website, the download completes and the file runs, but no verdict is ever returned from FortiSandbox. The administrator confirms that FortiSandbox is reachable and other protocols are being inspected successfully. Which action will most likely resolve the issue?

⚠ Common exam trap

The trap here is assuming that enabling FortiSandbox inspection in the antivirus profile is sufficient for all traffic types, ignoring that encrypted traffic must be decrypted first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable deep inspection in the SSL inspection profile applied to the policy.

File submission to FortiSandbox requires that FortiGate can see the file content. For HTTPS downloads, this means the traffic must be decrypted using an SSL inspection profile set to deep inspection. Without decryption, the antivirus engine cannot identify or extract the file, so no submission or verdict occurs. Enabling deep inspection on the policy resolves the issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable the 'Scan encrypted traffic' option in the antivirus profile.

    Why it's wrong here

    The antivirus profile does not have a 'Scan encrypted traffic' option; decryption is controlled by the SSL inspection profile. Even if such an option existed, it would not decrypt traffic without a proper deep-inspection profile. The administrator must apply an SSL inspection profile with deep inspection to the policy to allow file extraction from HTTPS.

  • ✓

    Enable deep inspection in the SSL inspection profile applied to the policy.

    Why this is correct

    FortiGate can only extract and submit files from HTTPS traffic if the session is decrypted. Without SSL deep inspection, the firewall sees only encrypted bytes and cannot identify the file for sandboxing, so no submission occurs. Enabling deep inspection allows the antivirus engine to inspect the decrypted payload and forward the executable to FortiSandbox for verdict.

  • ✗

    Change the FortiSandbox connection mode from FortiGate to inline.

    Why it's wrong here

    The connection mode determines how FortiGate communicates with FortiSandbox, not whether files are extracted from encrypted sessions. Inline mode is used when FortiSandbox is deployed as a gateway, but it does not decrypt HTTPS traffic on FortiGate. The failure to submit files stems from the lack of decryption, not from the sandbox integration mode.

  • ✗

    Add the website's IP address to the FortiSandbox blocklist.

    Why it's wrong here

    Adding an IP to a blocklist would prevent access to the site but would not enable file submission from HTTPS downloads. The issue is that files are not being extracted from encrypted traffic, not that the site is trusted or blocked. Blocklisting the IP does not address the missing SSL inspection and would not produce a sandbox verdict.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.