Courseiva
Advanced Threat Protection →mediumMultiple Choice

NSE7 Advanced Threat Protection Practice Question

A FortiGate running FortiOS 7.4 is configured with a firewall policy that references an IPS sensor. The sensor uses a custom signature to detect a recently discovered exploit. Users report that the exploit traffic is not being blocked even though the signature is enabled. The administrator confirms the traffic matches the signature and that the policy is in flow-based inspection mode. Which action should the administrator take to ensure the IPS sensor can block the exploit?

⚠ Common exam trap

The trap here is assuming that enabling a signature automatically blocks matching traffic, when the action must be explicitly set to block.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the IPS sensor action for the signature to 'block'.

An IPS sensor in FortiOS can contain multiple signatures and filters, each with an action that determines whether matching traffic is allowed, monitored, or blocked. If the action is not set to block, the sensor will not drop packets even when a signature matches. The administrator must verify the action for the specific signature and set it to block to achieve the desired protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set the IPS sensor action for the signature to 'block'.

    Why this is correct

    In FortiOS, an IPS sensor can have multiple filters and signatures, each with an action such as pass, block, or reset. If the signature action is set to 'pass' or 'monitor', traffic will not be blocked even if the signature matches. The administrator must explicitly set the action to 'block' for that signature to drop matching packets. This is the most direct fix for the described symptom.

  • ✗

    Enable 'Block malicious URLs' in the web filter profile.

    Why it's wrong here

    The web filter profile is used for URL filtering and does not control IPS signature actions. Enabling 'Block malicious URLs' would not affect the exploit traffic described, which is matched by a custom IPS signature. The scenario is about an IPS sensor, not web filtering. This option misdirects the administrator to an unrelated security profile that does not influence IPS blocking behavior.

  • ✗

    Add the signature to a custom application control signature.

    Why it's wrong here

    Application control signatures are used to identify and control applications, not to block exploits at the IPS level. Moving the signature to application control would not provide the same inspection and blocking capabilities for the exploit traffic. The IPS sensor already has the signature; the issue is the action assigned to it. This option incorrectly suggests changing the security profile type instead of correcting the IPS action.

  • ✗

    Change the firewall policy inspection mode to proxy-based.

    Why it's wrong here

    Proxy-based inspection does allow deeper inspection, but it is not required for IPS blocking in FortiOS 7.4. Flow-based IPS can block matching traffic when configured correctly. Changing to proxy-based would add latency and may not resolve the issue if the root cause is a missing action setting. The scenario states the policy is already in flow-based mode, and the signature matches, so the problem is likely the IPS sensor action, not the inspection mode.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.