NSE7 Advanced Threat Protection Practice Question
A FortiGate is configured with an IPS sensor that has protocol anomaly detection enabled. The admin notices that legitimate VoIP traffic (SIP) is being blocked. Which action should the admin take to reduce false positives?
⚠ Common exam trap
Candidates often think disabling or bypassing detection (options A, B, or C) is the simplest fix, but the exam tests the understanding that protocol anomaly detection should be tuned rather than disabled to preserve security while reducing false positives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tune the protocol anomaly thresholds to be more lenient for SIP
Protocol anomaly detection in IPS sensors uses predefined thresholds to identify abnormal traffic patterns. When legitimate SIP traffic is being blocked, tuning the protocol anomaly thresholds to be more lenient for SIP allows the sensor to accommodate normal variations in SIP behavior without triggering false positives, while still maintaining protection against actual anomalies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the IPS action from block to monitor
Why it's wrong here
Switching the action to monitor stops blocking but leaves the anomaly signature enabled, so the false positives persist and SIP traffic still triggers alerts rather than passing. Monitoring suits tuning phases where you want visibility before enforcing, not resolving a live VoIP outage.
- ✗
Add the VoIP servers to an IP exemption list in the IPS sensor
Why it's wrong here
An IP exemption list bypasses IPS inspection for the VoIP servers entirely, disabling anomaly detection for that traffic rather than tuning the SIP protocol anomaly that misfires. Exemptions suit trusted hosts that must never be inspected, not legitimate traffic a signature misclassifies.
- ✗
Disable protocol anomaly detection entirely
Why it's wrong here
Disabling protocol anomaly detection removes protection against malformed SIP and other protocol attacks across all traffic, far beyond the VoIP false positives. It is tempting as a quick fix, and would be correct only if anomaly detection itself were unusable in the environment.
- ✓
Tune the protocol anomaly thresholds to be more lenient for SIP
Why this is correct
Protocol anomaly detection flags SIP deviations from strict RFC behaviour, and legitimate VoIP implementations often violate these expectations. Raising the anomaly thresholds for SIP reduces sensitivity to benign variation, cutting false positives while retaining signature-based IPS coverage for actual attacks.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.