Courseiva
Advanced Threat Protection →mediumMultiple Choice

NSE7 Advanced Threat Protection Practice Question

A security analyst is investigating alerts from FortiGate's IPS. They notice that an attack was detected but not blocked, even though the IPS profile is set to block. The log shows the action as 'detected'. What is the most likely reason for this behavior?

⚠ Common exam trap

The trap here is assuming that setting the IPS profile to block automatically blocks all signatures, when individual signature actions can override the profile setting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IPS signature is set to 'Monitor' instead of 'Block' in the IPS sensor.

The most likely reason is that the specific IPS signature that detected the attack is configured to 'Monitor' rather than 'Block' in the IPS sensor. Even if the overall profile is set to block, individual signatures can override this. Checking the signature's action setting in the sensor will confirm and allow correction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The FortiGate's IPS engine is in 'learn' mode.

    Why it's wrong here

    FortiGate does not have a 'learn' mode for IPS. IPS profiles can be in 'block' or 'monitor' mode, but there is no global learn mode. The detection without blocking indicates a per-signature action setting, not an engine mode.

  • ✗

    The FortiGate is in transparent mode, which does not support IPS blocking.

    Why it's wrong here

    FortiGate in transparent mode supports IPS blocking. Transparent mode operates at Layer 2, but IPS still inspects and can block traffic. The mode does not inherently prevent blocking; many deployments use transparent mode with IPS. So this is not the reason.

  • ✓

    The IPS signature is set to 'Monitor' instead of 'Block' in the IPS sensor.

    Why this is correct

    In FortiGate, each IPS signature within a sensor can be individually set to 'Block' or 'Monitor'. If a signature is set to 'Monitor', it will detect and log the attack but not block it, even if the overall profile is set to block. This is the most likely cause of the observed behavior.

  • ✗

    The IPS profile is applied to the wrong firewall policy.

    Why it's wrong here

    If the IPS profile were applied to the wrong policy, the attack might not be inspected at all, resulting in no detection. However, the log shows detection, meaning the traffic was inspected by an IPS profile. Therefore, the profile is applied correctly, but the action is not blocking.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.