Courseiva
Advanced Threat Protection →mediumMultiple Choice

NSE7 Advanced Threat Protection Practice Question

A network security administrator notices that FortiGate is not blocking outbound traffic to domains that FortiGuard classifies as malicious. The administrator confirms that the license is valid and FortiGuard category-based blocking is enabled. Which FortiGate feature should be verified to ensure that DNS queries for malicious domains are intercepted and sinkholed?

⚠ Common exam trap

The trap here is assuming that FortiGuard category-based web filtering alone will block all malicious domains, but it does not intercept DNS queries unless DNS filtering with botnet C&C blocking is enabled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS filter with botnet C&C domain blocking enabled

The DNS filter with botnet C&C domain blocking is designed to intercept DNS responses for known malicious domains and redirect them to a sinkhole, effectively preventing communication. This is the correct mechanism when the goal is to block DNS resolution of malicious domains. Other features operate at different layers and do not provide DNS-level sinkholing, so they would not address the specific problem.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Web filter with FortiGuard category-based blocking

    Why it's wrong here

    Web filter category blocking operates on HTTP/HTTPS traffic after DNS resolution, not on DNS queries themselves. It would not prevent the initial DNS resolution of a malicious domain, and if the domain is not categorized under a blocked category, it may still be allowed. This does not ensure DNS sinkholing.

  • ✗

    Application control with botnet signatures

    Why it's wrong here

    Application control identifies and controls applications based on behavioral patterns, not DNS resolution. While it can block botnet communication, it does not intercept DNS queries for malicious domains. It operates at a different layer and would not sinkhole DNS requests as required.

  • ✓

    DNS filter with botnet C&C domain blocking enabled

    Why this is correct

    FortiGate's DNS filter, when configured with botnet C&C domain blocking, intercepts DNS responses for known malicious domains and redirects them to a sinkhole IP, preventing resolution. This directly addresses the scenario where malicious domains are not being blocked despite FortiGuard category blocking being active, because category blocking alone may not cover all C&C domains unless DNS filtering is enforced.

  • ✗

    Antivirus profile with botnet C&C IP blocking

    Why it's wrong here

    Antivirus profiles scan files and block known malware signatures, and may include botnet IP blocking, but they do not handle DNS resolution. They cannot intercept DNS queries to sinkhole malicious domains, so they would not solve the described issue.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.