NSE7 Advanced Threat Protection Practice Question
A security analyst wants to use automation stitches on FortiGate to automatically block IP addresses that trigger an IPS signature for 'SSH Brute Force'. Which two components are required to create this automation stitch? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse optional actions like email notifications or external log queries as required components, when only the trigger and a blocking action are mandatory to create a functional automation stitch for IP blocking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Action: 'Add to Block List'
Option A ('Add to Block List') is correct because the automation stitch must contain an action that actually enforces the block; the 'Add to Block List' action inserts the offending source IP into the FortiGate's local block list so subsequent traffic from that address is dropped. Option D ('IPS Event') is correct because the stitch needs a trigger that fires when the IPS signature for 'SSH Brute Force' is detected, and the IPS Event trigger is the mechanism that initiates the automation stitch upon an IPS log event. Together, the IPS Event trigger and the Add to Block List action form the required trigger-plus-action pair for this scenario. Option B (FortiAnalyzer log query) is not required because automation stitches on FortiGate are triggered by local event/log conditions, not by querying FortiAnalyzer. Option C (Email Notification) is an action that would only notify someone rather than block the IP, so it does not fulfill the blocking requirement. Option E (FortiGuard category) relates to web filtering categorization and is unrelated to blocking an IP that triggered an IPS signature.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Action: 'Add to Block List'
Why this is correct
'Add to Block List' is the action component that performs the blocking. The stitch needs a trigger to fire and an action to execute; this action quarantines the offending source IP on FortiGate, satisfying the requirement to automatically block addresses matching the SSH Brute Force IPS signature.
- ✗
FortiAnalyzer log query
Why it's wrong here
Automation stitches trigger on local FortiGate event logs, so an external FortiAnalyzer log query is not a valid trigger here. It tempts because FortiAnalyzer is the central log repository, and querying it would be right when correlating events across multiple devices rather than reacting to one firewall's IPS log.
- ✗
Action: 'Email Notification'
Why it's wrong here
Email Notification only reports the event to an administrator; it performs no address blocking, so the SSH brute-force source stays permitted. It tempts because notification actions are common in stitches, and this would be correct when the requirement is alerting staff rather than automatically denying the offending IP.
- ✓
Trigger: 'IPS Event'
Why this is correct
'IPS Event' is the trigger component that fires when the SSH Brute Force signature matches. Automation stitches pair one trigger with one or more actions, so this event detection initiates the workflow that subsequently blocks the offending IP address.
- ✗
FortiGuard category
Why it's wrong here
FortiGuard categories classify web-filter and DNS traffic, not IPS signature events, so they cannot trigger on an SSH brute-force signature. It tempts because FortiGuard feeds drive many blocking policies, and this would be correct when the trigger is a category lookup rather than an IPS log.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.