Courseiva

NSE7 Advanced Threat Protection Practice Question

A security administrator is configuring a FortiGate to use a threat feed connector to block traffic from known malicious IP addresses. The administrator wants to ensure that the threat feed is updated automatically and that the FortiGate can use the feed in firewall policies. Which two actions must the administrator perform? (Choose two.)

⚠ Common exam trap

The trap here is thinking that enabling an antivirus block list option or applying the connector to SSL inspection is required, when the feed is actually enforced through a dynamic address object in a firewall policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the threat feed as an external connector of type 'IP Address'.

To use a custom threat feed for blocking, the administrator must configure an external connector of type 'IP Address' and then reference the resulting dynamic address object in a firewall policy with a deny action. The refresh interval should be set to a non-zero value for automatic updates. Other options such as antivirus block lists or SSL inspection profiles are not involved in this integration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable 'Use External IP Block List' in the antivirus profile.

    Why it's wrong here

    The 'Use External IP Block List' option in the antivirus profile is used to block IP addresses from a specific FortiGuard block list, not for custom threat feeds. Custom threat feeds are integrated via external connectors and dynamic address objects. Enabling this option would not make the custom threat feed functional in firewall policies. The administrator should focus on the connector and policy configuration instead.

  • ✗

    Set the threat feed refresh interval to 0 to disable automatic updates.

    Why it's wrong here

    Setting the refresh interval to 0 would disable automatic updates, which is contrary to the requirement that the feed be updated automatically. The administrator should configure a non-zero refresh interval, such as 5 minutes, to ensure the FortiGate periodically retrieves the latest feed. Disabling updates would leave the FortiGate with stale data and reduce protection against newly identified malicious IPs.

  • ✓

    Configure the threat feed as an external connector of type 'IP Address'.

    Why this is correct

    In FortiOS, threat feeds are configured as external connectors. For IP address feeds, the type must be 'IP Address' so that the FortiGate can parse the feed and create a dynamic address object. This object can then be referenced in firewall policies to block or allow traffic. Without the correct connector type, the feed may not be usable as an address object, and the FortiGate will not enforce policies based on the feed.

  • ✗

    Apply the threat feed connector to the SSL inspection profile.

    Why it's wrong here

    SSL inspection profiles are used to decrypt and inspect SSL/TLS traffic; they do not consume threat feed connectors. Threat feeds are consumed via external connectors and dynamic address objects in firewall policies. Applying the connector to an SSL inspection profile would have no effect on blocking IP addresses from the feed. This option confuses the integration point for threat feeds with SSL inspection settings.

  • ✓

    Create a firewall policy that references the dynamic address object created from the threat feed.

    Why this is correct

    After configuring the external connector, FortiOS automatically creates a dynamic address object that is populated with the IP addresses from the feed. To enforce blocking, the administrator must create a firewall policy that uses this dynamic address object as the source or destination. The policy action should be set to deny. Without a policy referencing the object, the feed data is not used for traffic filtering.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.