Courseiva

NSE7 Advanced Threat Protection Practice Question

A security analyst is reviewing FortiGate logs and notices that several internal hosts are repeatedly connecting to a domain that is known to host malware. The domain is not present in any local or FortiGuard category. The analyst wants to automatically block future connections to this domain and similar malicious domains without manual intervention. Which FortiGate feature should be configured to achieve this?

⚠ Common exam trap

The trap here is assuming that FortiGuard categories automatically include all malicious domains, overlooking the need for local threat intelligence and automation to handle zero-day or uncategorized threats.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Local threat intelligence feed with automation stitch

The scenario requires automatic blocking of a newly discovered malicious domain that is not categorized by FortiGuard. A local threat intelligence feed can be updated dynamically via automation stitches triggered by log events, enabling FortiGate to block the domain and similar ones. DNS filter and application control rely on static or FortiGuard-provided intelligence, and IoT detection is unrelated. Thus, the local threat feed with automation stitch is the correct solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS filter with botnet C&C category

    Why it's wrong here

    The DNS filter with botnet C&C category blocks domains that FortiGuard classifies as command and control. However, the domain in question is not in any FortiGuard category, so it would not be blocked. This feature relies on FortiGuard intelligence and does not automatically learn new malicious domains from local traffic. Thus it does not meet the requirement for automatic blocking of uncategorized malicious domains.

  • ✓

    Local threat intelligence feed with automation stitch

    Why this is correct

    A local threat intelligence feed can be populated with the malicious domain, and an automation stitch can be triggered by a log event to add the domain to the feed automatically. This allows FortiGate to block future connections without manual intervention. The combination of a local threat feed and automation stitch provides the dynamic blocking required, as FortiGate can update the feed based on detected events.

  • ✗

    Application control with custom signature

    Why it's wrong here

    Application control with a custom signature can block traffic based on application characteristics, but creating a signature for a domain is not typical and would require manual creation and maintenance. It does not automatically learn from logs. This approach is static and does not provide the automated, dynamic blocking needed for an emerging malicious domain.

  • ✗

    FortiGuard IoT detection service

    Why it's wrong here

    FortiGuard IoT detection identifies and categorizes IoT devices on the network. It does not block domains or provide threat intelligence for malicious domains. While it can help inventory devices, it is not designed for blocking connections to malicious domains. This feature is irrelevant to the scenario, which requires automated blocking of a malicious domain.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.