Courseiva
Advanced Threat Protection →mediumMultiple Choice

NSE7 Advanced Threat Protection Practice Question

A security administrator is deploying FortiDeceptor in a data center network. They want to detect an attacker who is performing internal reconnaissance by scanning the subnet for live hosts. Which FortiDeceptor component should the administrator deploy to generate a decoy IP address that responds to such scans and alerts on any interaction?

⚠ Common exam trap

The trap here is assuming that any monitoring interface or logging tool can act as a decoy, when FortiDeceptor requires an active decoy VM or network decoy to generate responses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy a FortiDeceptor decoy VM that uses a decoy IP address on the same subnet.

FortiDeceptor uses decoy VMs, network decoys, and token decoys to lure attackers. A decoy VM with a decoy IP on the same subnet is the correct component to detect internal reconnaissance scans because it appears as a live host and alerts on any interaction. Other options either provide passive monitoring, lack decoy functionality, or are analytics tools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use FortiAnalyzer to create a synthetic network device that logs scan attempts.

    Why it's wrong here

    FortiAnalyzer is a logging and analytics platform; it does not create synthetic network devices or decoy IP addresses. It can collect and correlate logs from FortiDeceptor, but it cannot itself generate a decoy that responds to scans. The requirement is for an active deception component, not a log collector.

  • ✓

    Deploy a FortiDeceptor decoy VM that uses a decoy IP address on the same subnet.

    Why this is correct

    A FortiDeceptor decoy VM is a lightweight virtual machine that mimics a real host and is assigned a decoy IP address on the target subnet. When an attacker scans the subnet, the decoy responds like a legitimate host, and any interaction generates an alert, enabling early detection of internal reconnaissance.

  • ✗

    Configure a FortiGate interface as a honeypot by enabling the decoy option in the firewall policy.

    Why it's wrong here

    FortiGate does not have a built-in 'decoy' option in firewall policies to create honeypot IP addresses. While FortiGate can integrate with FortiDeceptor, it cannot itself act as a decoy host. The scenario requires a dedicated deception solution, not a firewall policy setting.

  • ✗

    Install a FortiDeceptor virtual appliance in promiscuous mode on a SPAN port.

    Why it's wrong here

    A SPAN port or promiscuous mode only copies traffic for passive monitoring; it cannot generate a decoy IP address or respond to scans. FortiDeceptor requires active decoy VMs or network decoys to attract and detect attackers, so this mode would not create a lure that triggers alerts on reconnaissance.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.