NSE7 Advanced Threat Protection Practice Question
A security analyst is investigating alerts from FortiGate's IPS. They notice that an attack was detected but not blocked, even though the IPS profile is set to block. The log shows the action as 'detected'. What is the most likely reason for this behavior?
⚠ Common exam trap
The trap here is assuming that setting the IPS profile to block automatically blocks all signatures, when individual signature actions can override the profile setting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IPS signature is set to 'Monitor' instead of 'Block' in the IPS sensor.
The most likely reason is that the specific IPS signature that detected the attack is configured to 'Monitor' rather than 'Block' in the IPS sensor. Even if the overall profile is set to block, individual signatures can override this. Checking the signature's action setting in the sensor will confirm and allow correction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The FortiGate's IPS engine is in 'learn' mode.
Why it's wrong here
FortiGate does not have a 'learn' mode for IPS. IPS profiles can be in 'block' or 'monitor' mode, but there is no global learn mode. The detection without blocking indicates a per-signature action setting, not an engine mode.
- ✗
The FortiGate is in transparent mode, which does not support IPS blocking.
Why it's wrong here
FortiGate in transparent mode supports IPS blocking. Transparent mode operates at Layer 2, but IPS still inspects and can block traffic. The mode does not inherently prevent blocking; many deployments use transparent mode with IPS. So this is not the reason.
- ✓
The IPS signature is set to 'Monitor' instead of 'Block' in the IPS sensor.
Why this is correct
In FortiGate, each IPS signature within a sensor can be individually set to 'Block' or 'Monitor'. If a signature is set to 'Monitor', it will detect and log the attack but not block it, even if the overall profile is set to block. This is the most likely cause of the observed behavior.
- ✗
The IPS profile is applied to the wrong firewall policy.
Why it's wrong here
If the IPS profile were applied to the wrong policy, the attack might not be inspected at all, resulting in no detection. However, the log shows detection, meaning the traffic was inspected by an IPS profile. Therefore, the profile is applied correctly, but the action is not blocking.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.