Courseiva
Advanced Threat Protection →mediumMultiple Select

NSE7 Advanced Threat Protection Practice Question

A security administrator is configuring FortiGate to detect and block command-and-control (C2) traffic using the botnet database and DNS filtering. The administrator wants to ensure that infected internal hosts are identified and their C2 communication is blocked. Which two actions should the administrator take? (Choose two.)

⚠ Common exam trap

The trap here is selecting monitor-only IPS or manual deny policies instead of using the automated, intelligence-driven botnet database and DNS filtering that are designed for C2 blocking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a DNS filter profile with FortiGuard category filtering and block malicious categories.

To detect and block C2 traffic, the administrator should enable the botnet database with a block action in the antivirus profile and configure DNS filtering to block malicious categories. These two actions provide both IP-based and domain-based blocking of C2 communication, and they leverage FortiGuard threat intelligence. Together they help identify infected hosts and prevent them from reaching C2 infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable logging for botnet events to reduce log volume.

    Why it's wrong here

    Disabling logging for botnet events would remove visibility into C2 detections and hinder incident response. The administrator needs to identify infected hosts, which requires logging. Reducing log volume by disabling security event logs is counterproductive and does not help block C2 traffic. This action is not appropriate for the scenario.

  • ✗

    Create a firewall address for each known C2 server and manually add them to a deny policy.

    Why it's wrong here

    Manually creating addresses for each C2 server is not scalable and will quickly become outdated as C2 infrastructure changes. It does not leverage FortiGuard threat intelligence and cannot keep up with dynamic C2. While a deny policy can block traffic, this approach is operationally inefficient and not the recommended method for blocking known C2.

  • ✗

    Enable IPS signatures for known C2 protocols and set the action to monitor only.

    Why it's wrong here

    Setting IPS signatures to monitor only will log detected C2 traffic but will not block it. The requirement is to block C2 communication, so monitor-only mode is insufficient. While IPS can detect some C2 patterns, the action must be set to block to meet the objective, and it should be combined with other layers for comprehensive coverage.

  • ✓

    Configure a DNS filter profile with FortiGuard category filtering and block malicious categories.

    Why this is correct

    DNS filtering with FortiGuard category filtering can block DNS resolutions for known malicious domains, preventing hosts from reaching C2 servers by domain name. This complements IP-based botnet blocking and helps stop C2 that uses domain names. It is an effective action for identifying and blocking C2 communication at the DNS layer.

  • ✓

    Enable the botnet database in the antivirus profile and set the action to block.

    Why this is correct

    The botnet database in the antivirus profile allows FortiGate to detect connections to known C2 servers and block them. Enabling it with a block action ensures that infected hosts cannot communicate with those C2 endpoints. This is a core component of advanced threat protection on FortiGate and directly addresses the requirement to block C2 traffic.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.