Courseiva

NSE7 Advanced Threat Protection Practice Question

A network administrator is configuring a FortiGate to protect against unknown malware by using machine learning. The administrator wants to enable the feature that uses machine learning to detect and block malicious files based on their behavior and characteristics, without relying solely on signatures. Which antivirus setting should the administrator enable?

⚠ Common exam trap

Many candidates confuse machine learning malware detection with sandboxing or outbreak prevention, which are different technologies for handling unknown threats.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Machine Learning (ML) Malware Detection

The Machine Learning Malware Detection setting in the FortiGate antivirus profile uses machine learning algorithms to detect and block unknown malware based on file characteristics and behavior. This provides protection against zero-day threats without relying solely on signatures, meeting the administrator's requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Sandbox Inspection

    Why it's wrong here

    Sandbox Inspection sends files to FortiSandbox for dynamic analysis, which is not machine learning on the FortiGate itself. While it can detect unknown malware, it relies on external sandboxing and is not the machine learning feature built into the antivirus profile. The question specifically asks for a machine learning setting, so this is incorrect.

  • ✓

    Machine Learning (ML) Malware Detection

    Why this is correct

    The Machine Learning Malware Detection setting in the antivirus profile uses machine learning models to analyze file characteristics and behavior to identify and block unknown malware. This is exactly what the administrator needs to protect against unknown threats without relying solely on signatures. It is a built-in FortiGate feature available in the antivirus profile.

  • ✗

    FortiGuard Outbreak Prevention

    Why it's wrong here

    FortiGuard Outbreak Prevention is a separate feature that blocks known outbreak-related threats using dynamic intelligence. It is not a machine learning antivirus setting. While it enhances protection, it does not provide the machine learning-based detection of unknown malware that the administrator seeks. Enabling it would not fulfill the requirement for machine learning antivirus.

  • ✗

    Content Disarm and Reconstruction

    Why it's wrong here

    Content Disarm and Reconstruction (CDR) is a technique that removes potentially malicious content from files, rather than using machine learning to detect malware. It is not an antivirus setting that uses machine learning. CDR is effective for certain file types but does not provide the behavioral machine learning detection described in the scenario.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.