Courseiva

NSE7 Advanced Threat Protection Practice Question

A security analyst is investigating an alert from FortiSandbox indicating that a file has a high-risk verdict. The analyst wants to automatically prevent the file from executing on other endpoints. Which FortiSandbox integration should be configured to achieve this?

⚠ Common exam trap

The trap here is assuming that any fabric connector will automatically block the file everywhere, but only the FortiGate integration can enforce blocking at the network perimeter for all traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

FortiSandbox to FortiGate fabric connector

Configuring the fabric connector between FortiSandbox and FortiGate allows automatic sharing of malicious file verdicts. FortiGate can then block the file hash, preventing download and execution on endpoints. Other fabric connectors are limited to email security, endpoint management, or logging, and do not provide the same automatic network-wide blocking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    FortiSandbox to FortiAnalyzer fabric connector

    Why it's wrong here

    The FortiAnalyzer fabric connector is used for logging and reporting, not for active enforcement. It allows FortiSandbox to send logs and verdicts to FortiAnalyzer for analysis and correlation, but FortiAnalyzer does not block traffic or prevent file execution. Therefore, this integration does not meet the requirement to automatically prevent execution on endpoints.

  • ✓

    FortiSandbox to FortiGate fabric connector

    Why this is correct

    The fabric connector between FortiSandbox and FortiGate enables automatic sharing of verdicts. When FortiSandbox identifies a malicious file, it can send the file hash and other indicators to FortiGate, which then adds them to its local blocklist. This prevents the file from being downloaded or executed on endpoints protected by that FortiGate. This integration directly addresses the requirement to automatically block the file across the network.

  • ✗

    FortiSandbox to FortiClient EMS fabric connector

    Why it's wrong here

    The FortiClient EMS fabric connector allows FortiSandbox to share threat intelligence with FortiClient EMS, which can then enforce endpoint policies. While this can block execution on endpoints, it requires FortiClient to be installed and managed by EMS. The scenario does not specify that endpoints are managed by EMS, and the more direct and common integration for network-wide blocking is with FortiGate. Thus, this option is not the best fit.

  • ✗

    FortiSandbox to FortiMail fabric connector

    Why it's wrong here

    The FortiMail fabric connector allows FortiSandbox to share verdicts with FortiMail, which can then block malicious email attachments. However, this only protects email traffic and does not prevent the file from executing on endpoints if it arrives via other vectors like web downloads or USB drives. The scenario requires blocking execution on endpoints, so this integration is insufficient.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.