NSE7 Advanced Threat Protection Practice Question
A security analyst is reviewing logs from a FortiGate that uses FortiGuard IPS. The analyst notices that a signature for a recent Apache Struts vulnerability is not triggering even though the vulnerable service is exposed. The FortiGate is running the latest IPS engine and signature database. Which action should the analyst take to verify whether the signature is enabled and properly applied to the traffic?
⚠ Common exam trap
The trap here is jumping to advanced troubleshooting like debug logging before verifying that the signature is enabled and applied to the correct policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the IPS sensor configuration to ensure the signature is set to 'Block' and the sensor is applied to the correct firewall policy.
When an IPS signature does not trigger, the first step is to confirm that the signature is enabled in the IPS sensor and that the sensor is applied to the firewall policy processing the traffic. Without this, the signature will never be evaluated. Other troubleshooting steps like packet capture or debug logging are useful but secondary to verifying the basic configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Verify that the FortiGate has a valid FortiGuard license and can reach the FortiGuard servers.
Why it's wrong here
The scenario states the IPS engine and signature database are up to date, implying licensing and connectivity are fine. Checking the license again is redundant and does not address why the signature is not triggering. The focus should be on configuration and application of the IPS sensor.
- ✗
Run a packet capture on the FortiGate to confirm the traffic is reaching the IPS engine.
Why it's wrong here
While packet capture can confirm traffic flow, it does not verify whether the IPS signature is enabled or applied. The issue is likely configuration, not traffic delivery. Packet capture would not reveal if the signature is set to block or if the sensor is attached to the policy.
- ✗
Enable IPS debug logging to see if the signature is being evaluated.
Why it's wrong here
Debug logging can show signature evaluation but is a more advanced step after confirming basic configuration. It would not directly fix the issue if the signature is disabled or the sensor is not applied. The first step should be to check the sensor and policy configuration.
- ✓
Check the IPS sensor configuration to ensure the signature is set to 'Block' and the sensor is applied to the correct firewall policy.
Why this is correct
The most likely cause is that the signature is not enabled or the IPS sensor is not applied to the policy handling the traffic. Verifying the sensor configuration and policy assignment directly addresses whether the signature is active and inspecting the relevant traffic. This is the correct troubleshooting step.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.