Courseiva
Advanced Threat Protection →mediumMultiple Choice

NSE7 Advanced Threat Protection Practice Question

A security administrator is configuring a FortiGate to use an external threat intelligence feed to block malicious IP addresses. The administrator wants the FortiGate to automatically update the list of malicious IPs from a threat feed and use it in firewall policies. Which FortiGate feature should be used?

⚠ Common exam trap

Many candidates confuse threat feeds with Geo IP or ISDB, which are not dynamic external feeds for malicious IPs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Threat feeds in Security Fabric > Fabric Connectors

Threat feeds in Fabric Connectors allow FortiGate to subscribe to external threat intelligence sources and automatically update dynamic firewall addresses. These addresses can be used in policies to block malicious IPs. Other options either provide static or geographic-based lists, not dynamic external feeds.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS filter with a threat feed category

    Why it's wrong here

    DNS filter can block domains based on FortiGuard categories or static entries, but it does not ingest external IP threat feeds. It operates at the DNS layer and is not designed for IP-based blocking from custom feeds. This option does not fulfill the requirement to block malicious IP addresses from an external feed.

  • ✗

    Internet Service Database (ISDB) in firewall addresses

    Why it's wrong here

    ISDB provides predefined IP ranges for known services (e.g., Microsoft 365, AWS), not malicious IPs. It is used to simplify policy creation for trusted services. It does not support custom external threat feeds. Therefore, it cannot be used to block malicious IPs from an external source.

  • ✓

    Threat feeds in Security Fabric > Fabric Connectors

    Why this is correct

    FortiGate supports external threat feeds via Fabric Connectors, allowing the administrator to subscribe to a feed (e.g., TAXII, STIX, or plain text) and automatically update a dynamic firewall address. This address can then be used in firewall policies to block or allow traffic. This feature is designed for integrating external threat intelligence.

  • ✗

    Geo IP database in firewall addresses

    Why it's wrong here

    Geo IP addresses are used to block or allow traffic based on geographic location, not specific malicious IPs from an external feed. While Geo IP can be used for blocking entire countries, it does not provide dynamic updates from a threat intelligence feed. This does not meet the requirement.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.