NSE7 Advanced Threat Protection Practice Question
A security analyst is reviewing FortiGate logs and notices that several internal hosts are repeatedly connecting to a domain that is known to host malware. The domain is not present in any local or FortiGuard category. The analyst wants to automatically block future connections to this domain and similar malicious domains without manual intervention. Which FortiGate feature should be configured to achieve this?
⚠ Common exam trap
The trap here is assuming that FortiGuard categories automatically include all malicious domains, overlooking the need for local threat intelligence and automation to handle zero-day or uncategorized threats.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Local threat intelligence feed with automation stitch
The scenario requires automatic blocking of a newly discovered malicious domain that is not categorized by FortiGuard. A local threat intelligence feed can be updated dynamically via automation stitches triggered by log events, enabling FortiGate to block the domain and similar ones. DNS filter and application control rely on static or FortiGuard-provided intelligence, and IoT detection is unrelated. Thus, the local threat feed with automation stitch is the correct solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS filter with botnet C&C category
Why it's wrong here
The DNS filter with botnet C&C category blocks domains that FortiGuard classifies as command and control. However, the domain in question is not in any FortiGuard category, so it would not be blocked. This feature relies on FortiGuard intelligence and does not automatically learn new malicious domains from local traffic. Thus it does not meet the requirement for automatic blocking of uncategorized malicious domains.
- ✓
Local threat intelligence feed with automation stitch
Why this is correct
A local threat intelligence feed can be populated with the malicious domain, and an automation stitch can be triggered by a log event to add the domain to the feed automatically. This allows FortiGate to block future connections without manual intervention. The combination of a local threat feed and automation stitch provides the dynamic blocking required, as FortiGate can update the feed based on detected events.
- ✗
Application control with custom signature
Why it's wrong here
Application control with a custom signature can block traffic based on application characteristics, but creating a signature for a domain is not typical and would require manual creation and maintenance. It does not automatically learn from logs. This approach is static and does not provide the automated, dynamic blocking needed for an emerging malicious domain.
- ✗
FortiGuard IoT detection service
Why it's wrong here
FortiGuard IoT detection identifies and categorizes IoT devices on the network. It does not block domains or provide threat intelligence for malicious domains. While it can help inventory devices, it is not designed for blocking connections to malicious domains. This feature is irrelevant to the scenario, which requires automated blocking of a malicious domain.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.