Courseiva

NSE7 Advanced Threat Protection Practice Question

A network security administrator wants to use FortiGate to automatically quarantine an endpoint when FortiEDR detects malicious behavior on that endpoint. Which FortiGate feature should be used to integrate with FortiEDR for this purpose?

⚠ Common exam trap

A common mix-up: candidates confuse general network security profiles, such as antivirus or DNS filtering, with the specific Fabric Connector integration that enables automated endpoint quarantine based on FortiEDR detections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

FortiGate Fabric Connector for FortiEDR with automated response actions.

The FortiGate Fabric Connector for FortiEDR enables integration between the endpoint detection and response platform and the FortiGate. When FortiEDR identifies malicious behavior, the connector can trigger automated actions such as quarantining the endpoint or blocking its network access. This is the correct feature for coordinating endpoint detection with network enforcement in the Security Fabric.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    FortiGate IPsec VPN with dynamic routing to isolate the endpoint.

    Why it's wrong here

    IPsec VPN and dynamic routing are used for secure connectivity and path selection, not for endpoint quarantine based on threat detection. They do not integrate with FortiEDR and cannot automatically isolate a compromised endpoint. This option is unrelated to the automated response requirement and would not achieve the desired outcome.

  • ✗

    FortiGate antivirus profile with 'Block' action for all detected threats.

    Why it's wrong here

    An antivirus profile scans files for malware but does not receive endpoint detection events from FortiEDR or quarantine endpoints. It operates at the network file level and cannot enforce endpoint isolation. While it is a valuable security control, it does not fulfill the requirement to automatically quarantine an endpoint based on FortiEDR detections.

  • ✗

    FortiGate DNS filter with a blocklist of the endpoint's IP address.

    Why it's wrong here

    A DNS filter blocks domain resolutions, not endpoint traffic, and manually adding an endpoint IP to a blocklist is not an automated response to FortiEDR detection. This approach does not integrate with FortiEDR and would not quarantine the endpoint. It also fails to provide the dynamic, event-driven enforcement that the scenario requires.

  • ✓

    FortiGate Fabric Connector for FortiEDR with automated response actions.

    Why this is correct

    The FortiGate Fabric Connector for FortiEDR allows the FortiGate to receive threat information and trigger automated responses, including quarantining the endpoint or blocking its traffic. This integration is part of the Security Fabric and is the intended way to coordinate endpoint detection with network enforcement. It directly enables the automatic quarantine action described in the scenario.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.