NSE7 Advanced Threat Protection Practice Question
A security administrator is deploying FortiDeceptor in a data center network. They want to detect an attacker who is performing internal reconnaissance by scanning the subnet for live hosts. Which FortiDeceptor component should the administrator deploy to generate a decoy IP address that responds to such scans and alerts on any interaction?
⚠ Common exam trap
The trap here is assuming that any monitoring interface or logging tool can act as a decoy, when FortiDeceptor requires an active decoy VM or network decoy to generate responses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a FortiDeceptor decoy VM that uses a decoy IP address on the same subnet.
FortiDeceptor uses decoy VMs, network decoys, and token decoys to lure attackers. A decoy VM with a decoy IP on the same subnet is the correct component to detect internal reconnaissance scans because it appears as a live host and alerts on any interaction. Other options either provide passive monitoring, lack decoy functionality, or are analytics tools.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use FortiAnalyzer to create a synthetic network device that logs scan attempts.
Why it's wrong here
FortiAnalyzer is a logging and analytics platform; it does not create synthetic network devices or decoy IP addresses. It can collect and correlate logs from FortiDeceptor, but it cannot itself generate a decoy that responds to scans. The requirement is for an active deception component, not a log collector.
- ✓
Deploy a FortiDeceptor decoy VM that uses a decoy IP address on the same subnet.
Why this is correct
A FortiDeceptor decoy VM is a lightweight virtual machine that mimics a real host and is assigned a decoy IP address on the target subnet. When an attacker scans the subnet, the decoy responds like a legitimate host, and any interaction generates an alert, enabling early detection of internal reconnaissance.
- ✗
Configure a FortiGate interface as a honeypot by enabling the decoy option in the firewall policy.
Why it's wrong here
FortiGate does not have a built-in 'decoy' option in firewall policies to create honeypot IP addresses. While FortiGate can integrate with FortiDeceptor, it cannot itself act as a decoy host. The scenario requires a dedicated deception solution, not a firewall policy setting.
- ✗
Install a FortiDeceptor virtual appliance in promiscuous mode on a SPAN port.
Why it's wrong here
A SPAN port or promiscuous mode only copies traffic for passive monitoring; it cannot generate a decoy IP address or respond to scans. FortiDeceptor requires active decoy VMs or network decoys to attract and detect attackers, so this mode would not create a lure that triggers alerts on reconnaissance.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.