NSE7 Advanced Threat Protection Practice Question
A network security administrator notices that FortiGate is not blocking outbound traffic to domains that FortiGuard classifies as malicious. The administrator confirms that the license is valid and FortiGuard category-based blocking is enabled. Which FortiGate feature should be verified to ensure that DNS queries for malicious domains are intercepted and sinkholed?
⚠ Common exam trap
The trap here is assuming that FortiGuard category-based web filtering alone will block all malicious domains, but it does not intercept DNS queries unless DNS filtering with botnet C&C blocking is enabled.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS filter with botnet C&C domain blocking enabled
The DNS filter with botnet C&C domain blocking is designed to intercept DNS responses for known malicious domains and redirect them to a sinkhole, effectively preventing communication. This is the correct mechanism when the goal is to block DNS resolution of malicious domains. Other features operate at different layers and do not provide DNS-level sinkholing, so they would not address the specific problem.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Web filter with FortiGuard category-based blocking
Why it's wrong here
Web filter category blocking operates on HTTP/HTTPS traffic after DNS resolution, not on DNS queries themselves. It would not prevent the initial DNS resolution of a malicious domain, and if the domain is not categorized under a blocked category, it may still be allowed. This does not ensure DNS sinkholing.
- ✗
Application control with botnet signatures
Why it's wrong here
Application control identifies and controls applications based on behavioral patterns, not DNS resolution. While it can block botnet communication, it does not intercept DNS queries for malicious domains. It operates at a different layer and would not sinkhole DNS requests as required.
- ✓
DNS filter with botnet C&C domain blocking enabled
Why this is correct
FortiGate's DNS filter, when configured with botnet C&C domain blocking, intercepts DNS responses for known malicious domains and redirects them to a sinkhole IP, preventing resolution. This directly addresses the scenario where malicious domains are not being blocked despite FortiGuard category blocking being active, because category blocking alone may not cover all C&C domains unless DNS filtering is enforced.
- ✗
Antivirus profile with botnet C&C IP blocking
Why it's wrong here
Antivirus profiles scan files and block known malware signatures, and may include botnet IP blocking, but they do not handle DNS resolution. They cannot intercept DNS queries to sinkhole malicious domains, so they would not solve the described issue.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.