Courseiva

NSE7 Advanced Threat Protection Practice Question

A network administrator is deploying FortiGate to protect against unknown malware. They want to use machine learning to detect and block malicious files without relying on signatures. Which antivirus scanning technique should be enabled to achieve this?

⚠ Common exam trap

The trap here is equating heuristic scanning or sandboxing with machine learning, when they are distinct technologies with different detection methodologies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Machine learning-based malware detection

Machine learning-based malware detection uses artificial intelligence models to analyze file features and identify malicious patterns, allowing FortiGate to block unknown malware without relying on signatures. This is the only option that directly matches the requirement for machine learning. Other techniques like signatures, heuristics, or sandboxing are different approaches and do not provide the same capability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Heuristic scanning

    Why it's wrong here

    Heuristic scanning uses rules and behavior patterns to detect potentially malicious files, but it is not machine learning-based. It can catch some unknown variants but is less effective than machine learning models. The scenario asks for machine learning, so heuristic scanning alone does not fulfill the requirement, though it may complement other methods.

  • ✗

    Signature-based detection

    Why it's wrong here

    Signature-based detection relies on known malware signatures and cannot detect unknown malware. The scenario specifically requires machine learning to detect unknown threats, so this technique is insufficient. While it is a foundational part of antivirus protection, it does not meet the requirement for machine learning-based detection of unknown malware.

  • ✓

    Machine learning-based malware detection

    Why this is correct

    Machine learning-based malware detection uses trained models to identify malicious characteristics in files, enabling detection of unknown malware without signatures. FortiGate's antivirus profile includes this as an option, often labeled as 'AI-based' or 'Machine Learning' detection. It is designed to catch zero-day threats and is the correct choice for the scenario.

  • ✗

    Sandbox analysis

    Why it's wrong here

    Sandbox analysis detonates files in an isolated environment to observe behavior, which can detect unknown malware, but it is not a machine learning technique. It is a separate feature that may be used in conjunction with machine learning. The scenario specifically requests machine learning, so sandbox analysis is not the correct answer.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.