Courseiva

NSE7 Advanced Threat Protection Practice Question

A security analyst wants to use automation stitches on FortiGate to automatically block IP addresses that trigger an IPS signature for 'SSH Brute Force'. Which two components are required to create this automation stitch? (Choose two.)

⚠ Common exam trap

Test-takers frequently confuse optional actions like email notifications or external log queries as required components, when only the trigger and a blocking action are mandatory to create a functional automation stitch for IP blocking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Action: 'Add to Block List'

Option A ('Add to Block List') is correct because the automation stitch must contain an action that actually enforces the block; the 'Add to Block List' action inserts the offending source IP into the FortiGate's local block list so subsequent traffic from that address is dropped. Option D ('IPS Event') is correct because the stitch needs a trigger that fires when the IPS signature for 'SSH Brute Force' is detected, and the IPS Event trigger is the mechanism that initiates the automation stitch upon an IPS log event. Together, the IPS Event trigger and the Add to Block List action form the required trigger-plus-action pair for this scenario. Option B (FortiAnalyzer log query) is not required because automation stitches on FortiGate are triggered by local event/log conditions, not by querying FortiAnalyzer. Option C (Email Notification) is an action that would only notify someone rather than block the IP, so it does not fulfill the blocking requirement. Option E (FortiGuard category) relates to web filtering categorization and is unrelated to blocking an IP that triggered an IPS signature.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Action: 'Add to Block List'

    Why this is correct

    'Add to Block List' is the action component that performs the blocking. The stitch needs a trigger to fire and an action to execute; this action quarantines the offending source IP on FortiGate, satisfying the requirement to automatically block addresses matching the SSH Brute Force IPS signature.

  • ✗

    FortiAnalyzer log query

    Why it's wrong here

    Automation stitches trigger on local FortiGate event logs, so an external FortiAnalyzer log query is not a valid trigger here. It tempts because FortiAnalyzer is the central log repository, and querying it would be right when correlating events across multiple devices rather than reacting to one firewall's IPS log.

  • ✗

    Action: 'Email Notification'

    Why it's wrong here

    Email Notification only reports the event to an administrator; it performs no address blocking, so the SSH brute-force source stays permitted. It tempts because notification actions are common in stitches, and this would be correct when the requirement is alerting staff rather than automatically denying the offending IP.

  • ✓

    Trigger: 'IPS Event'

    Why this is correct

    'IPS Event' is the trigger component that fires when the SSH Brute Force signature matches. Automation stitches pair one trigger with one or more actions, so this event detection initiates the workflow that subsequently blocks the offending IP address.

  • ✗

    FortiGuard category

    Why it's wrong here

    FortiGuard categories classify web-filter and DNS traffic, not IPS signature events, so they cannot trigger on an SSH brute-force signature. It tempts because FortiGuard feeds drive many blocking policies, and this would be correct when the trigger is a category lookup rather than an IPS log.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.