Courseiva

NSE7 Advanced Threat Protection Practice Question

A security analyst is reviewing FortiGate logs and notices that a known malicious file hash is being downloaded repeatedly, but the antivirus profile is not blocking it. The file is detected by FortiSandbox, and the FortiGate has a valid FortiGuard license. Which action should the analyst take to ensure the hash is blocked on subsequent downloads?

⚠ Common exam trap

The trap here is assuming that a FortiSandbox verdict automatically creates a hash-based block on FortiGate, when the administrator may need to explicitly add the hash to a custom list or threat feed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the file hash to a custom antivirus signature list or threat feed and enable it in the antivirus profile.

When a specific malicious file hash is known, the most direct and reliable way to block it on FortiGate is to add that hash to a custom antivirus signature or external threat feed and enable it in the antivirus profile. This ensures detection regardless of the delivery URL or protocol, and it integrates with existing antivirus scanning. It also avoids overblocking legitimate executables and does not depend solely on sandbox verdict propagation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable 'Treat Windows executable files as viruses' in the antivirus profile to block all executable downloads.

    Why it's wrong here

    Treating all Windows executables as viruses is a blunt control that would block legitimate software downloads and cause major operational disruption. It does not specifically target the known malicious hash, and it is not a proportionate response. The analyst needs to block the specific file, not all executables, so this setting is inappropriate here.

  • ✗

    Configure FortiSandbox to send a verdict to FortiGate and set the action to 'Block' in the sandbox profile.

    Why it's wrong here

    FortiSandbox verdicts can inform FortiGate, but the scenario states the file is already detected by FortiSandbox and still not blocked. Relying on the sandbox verdict alone may not block the hash if the verdict is not propagated as a blockable signature, and it does not provide a deterministic hash-based block for future downloads. The analyst needs a direct hash block.

  • ✗

    Enable the 'Block malicious URLs' option in the web filter profile so the download URL is blocked.

    Why it's wrong here

    Blocking malicious URLs in the web filter profile can prevent access to known bad sites, but it does not address a file hash that is already known to be malicious and is being delivered from a URL that may not be categorized as malicious. The requirement is to block the hash itself, so this action does not reliably stop the same file from being downloaded from a different location.

  • ✓

    Add the file hash to a custom antivirus signature list or threat feed and enable it in the antivirus profile.

    Why this is correct

    FortiGate antivirus can block files based on custom signatures or external threat feeds that include file hashes. Adding the hash to a custom list and referencing it in the antivirus profile ensures the file is detected and blocked on subsequent downloads, even if the URL changes. This directly addresses the known malicious hash and is the correct operational response.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.