Courseiva

NSE7 Advanced Threat Protection Practice Question

A FortiGate is configured with an IPS sensor that has protocol anomaly detection enabled. The admin notices that legitimate VoIP traffic (SIP) is being blocked. Which action should the admin take to reduce false positives?

⚠ Common exam trap

Candidates often think disabling or bypassing detection (options A, B, or C) is the simplest fix, but the exam tests the understanding that protocol anomaly detection should be tuned rather than disabled to preserve security while reducing false positives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tune the protocol anomaly thresholds to be more lenient for SIP

Protocol anomaly detection in IPS sensors uses predefined thresholds to identify abnormal traffic patterns. When legitimate SIP traffic is being blocked, tuning the protocol anomaly thresholds to be more lenient for SIP allows the sensor to accommodate normal variations in SIP behavior without triggering false positives, while still maintaining protection against actual anomalies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the IPS action from block to monitor

    Why it's wrong here

    Switching the action to monitor stops blocking but leaves the anomaly signature enabled, so the false positives persist and SIP traffic still triggers alerts rather than passing. Monitoring suits tuning phases where you want visibility before enforcing, not resolving a live VoIP outage.

  • ✗

    Add the VoIP servers to an IP exemption list in the IPS sensor

    Why it's wrong here

    An IP exemption list bypasses IPS inspection for the VoIP servers entirely, disabling anomaly detection for that traffic rather than tuning the SIP protocol anomaly that misfires. Exemptions suit trusted hosts that must never be inspected, not legitimate traffic a signature misclassifies.

  • ✗

    Disable protocol anomaly detection entirely

    Why it's wrong here

    Disabling protocol anomaly detection removes protection against malformed SIP and other protocol attacks across all traffic, far beyond the VoIP false positives. It is tempting as a quick fix, and would be correct only if anomaly detection itself were unusable in the environment.

  • ✓

    Tune the protocol anomaly thresholds to be more lenient for SIP

    Why this is correct

    Protocol anomaly detection flags SIP deviations from strict RFC behaviour, and legitimate VoIP implementations often violate these expectations. Raising the anomaly thresholds for SIP reduces sensitivity to benign variation, cutting false positives while retaining signature-based IPS coverage for actual attacks.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.