NSE7 Advanced Threat Protection Practice Question
A security analyst is investigating a recent security incident and wants to use FortiGate's Security Fabric to gather threat intelligence. The analyst needs to view detailed information about a detected threat, including the source, destination, and the specific IPS signature that triggered. Which FortiGate feature provides a centralized view of threat events and allows drill-down into individual incidents?
⚠ Common exam trap
Many exam-takers confuse proactive blocking features like Outbreak Prevention with analytical tools like FortiView, or assuming that external appliances like FortiAnalyzer are required for centralized views.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FortiView
FortiView is a built-in FortiGate feature that aggregates and visualizes threat events from multiple security functions, including IPS, antivirus, and web filtering. It allows administrators to drill down into specific incidents to see source, destination, and signature details, making it a powerful tool for threat investigation within the Security Fabric.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
FortiView
Why this is correct
FortiView provides a centralized dashboard that aggregates logs and events from various FortiGate features, including IPS, antivirus, and web filtering. It allows drill-down into specific threats, showing source, destination, and signature details. This makes it ideal for incident investigation and threat intelligence gathering within the Security Fabric.
- ✗
FortiAnalyzer
Why it's wrong here
FortiAnalyzer is a centralized logging and reporting appliance that can store and analyze logs from multiple FortiGate devices. While it provides detailed reports and can be used for incident investigation, the question specifies a FortiGate feature that provides a centralized view. FortiAnalyzer is a separate product, not a built-in FortiGate feature, and may require additional licensing. Thus, it is not the correct answer for a FortiGate feature.
- ✗
FortiSandbox
Why it's wrong here
FortiSandbox is a cloud or on-premises sandboxing solution that analyzes files for malicious behavior. It provides verdicts and reports on file analysis, but it does not offer a centralized view of all threat events across the network. It is focused on file analysis, not on aggregating and displaying IPS or other network threat events in a drill-down format.
- ✗
FortiGuard Outbreak Prevention
Why it's wrong here
FortiGuard Outbreak Prevention is a proactive blocking feature that uses threat intelligence to prevent outbreaks. It does not provide a centralized view or drill-down capability for past incidents. While it can block threats, it is not an analysis tool for investigating specific events, and it lacks the detailed event visualization that FortiView offers.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.