NSE7 Advanced Threat Protection Practice Question
A security administrator is reviewing threat logs on a FortiGate running FortiOS 7.4. Multiple internal hosts have triggered IPS signatures for a known botnet C2 domain, but the administrator wants to ensure that DNS queries to this domain are blocked before a connection is attempted. The FortiGate is already using the default FortiGuard ISDB and IPS signatures. Which FortiGate feature should the administrator configure to block DNS resolution of the malicious domain?
⚠ Common exam trap
The trap here is assuming that blocking a URL or application also blocks DNS resolution, but DNS filtering must be configured separately to prevent domain resolution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS filter profile with a static domain filter entry set to block
The DNS filter profile is designed to inspect DNS queries and can block resolution of specific domains using static domain filters. When applied to a policy, it prevents internal hosts from resolving malicious domains, effectively stopping connections before they start. Other features like web filter or application control operate at later stages and do not block DNS resolution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Web filter profile with a URL filter entry set to block
Why it's wrong here
A web filter profile with a URL filter blocks HTTP/HTTPS requests based on the URL, but it does not block DNS resolution. The host would still resolve the domain to an IP address and could attempt a direct connection or use another protocol. This does not satisfy the requirement to block DNS queries for the domain.
- ✗
IPS sensor with a custom signature that matches the domain name in DNS queries
Why it's wrong here
While a custom IPS signature could inspect DNS queries, it is not the intended feature for domain blocking and requires complex signature creation. The built-in DNS filter is purpose-built for this task and is simpler to manage. The IPS sensor approach is less efficient and more error-prone for blocking domain resolution.
- ✗
Application control profile with a signature to block the botnet application
Why it's wrong here
Application control identifies and blocks applications based on traffic patterns, but it does not prevent DNS resolution. The malicious domain could still be resolved, and the application might use a different protocol or port. This does not block the DNS query itself, so it fails the scenario requirement.
- ✓
DNS filter profile with a static domain filter entry set to block
Why this is correct
A DNS filter profile allows the administrator to create a static domain filter that blocks or allows specific domains. When applied to a firewall policy, FortiGate inspects DNS queries and blocks resolution for the malicious domain, preventing hosts from learning the IP address. This directly addresses the requirement to block DNS resolution before a connection is attempted.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.