NSE7 Advanced Threat Protection Practice Question
A security analyst is reviewing FortiGate logs and notices that a web filter profile is blocking access to a known malicious domain, but the block page shows the category as 'Unrated'. The analyst confirms the domain is listed in a custom blocklist. Which FortiGate feature is responsible for overriding the category and enforcing the block?
⚠ Common exam trap
The trap here is assuming that a block page always reflects the FortiGuard category action, when a static URL filter entry can enforce blocking independently of the category.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Static URL filter with the action set to 'Block' and the type set to 'Simple'.
A static URL filter entry with the action set to Block and type Simple allows an administrator to block specific URLs or domains regardless of their FortiGuard category. This is why a domain categorized as Unrated can still be blocked and present a block page. The static URL filter is evaluated as part of the web filter profile and overrides category-based actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Static URL filter with the action set to 'Block' and the type set to 'Simple'.
Why this is correct
A static URL filter entry of type 'Simple' can match a specific URL or domain and apply the 'Block' action regardless of the FortiGuard category. This override takes precedence over category-based filtering, which is why the domain is blocked even though it is categorized as 'Unrated'. The custom blocklist is implemented through static URL filter entries that are evaluated before category actions.
- ✗
FortiGuard web filter category override using a local category definition.
Why it's wrong here
Local category definitions allow administrators to assign custom categories to URLs, but they do not directly enforce a block action unless the category itself is set to block in the web filter profile. The scenario describes a specific blocklist entry, not a category reassignment. The block page showing 'Unrated' indicates the category was not changed, so a category override is not the mechanism.
- ✗
DNS filter with a custom blocklist entry for the domain.
Why it's wrong here
A DNS filter can block domains by returning a block response, but the scenario describes a web filter block page showing a category. DNS filtering would not produce a web filter block page with a category label. Additionally, DNS filtering is separate from web filter profiles and would not display the 'Unrated' category in the same way.
- ✗
Application control signature that matches the domain's HTTP header.
Why it's wrong here
Application control identifies applications based on protocol behavior and signatures, not specific domain names. While it can block certain applications, it does not use URL blocklists and would not show a web filter category. The block page and category display are functions of the web filter, not application control.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.