NSE7 Advanced Threat Protection Practice Question
A security engineer wants to implement advanced threat protection for email using FortiMail. Which THREE features should be enabled to provide comprehensive protection against sophisticated email threats? (Choose three.)
⚠ Common exam trap
The trap here is that candidates often mistake basic anti-spam or administrative controls (like attachment size limits) for advanced threat protection features, overlooking that sophisticated threats require dynamic, behavior-based defenses such as URL rewriting, sandboxing, and email authentication protocols.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
URL rewriting and click-time protection
URL rewriting and click-time protection (A) is correct because FortiMail rewrites embedded URLs and re-evaluates them when the user clicks, blocking advanced phishing and malicious links that were benign at delivery time. FortiSandbox integration for email attachments (B) is correct because it detonates suspicious attachments in an isolated sandbox to detect zero-day malware and advanced persistent threats that signature-based scanning misses. DMARC verification (D) is correct because it validates the alignment of SPF and DKIM with the From: domain, preventing domain spoofing and business email compromise. Anti-Spam filter (C) is not among the marked answers because it addresses bulk unsolicited mail rather than sophisticated targeted threats. Attachment size limits (E) are not among the marked answers because they only enforce message size policy and provide no threat detection capability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
URL rewriting and click-time protection
Why this is correct
URL rewriting converts embedded links into redirected FortiMail URLs, so every click is inspected at click time against live threat intelligence. This blocks weaponised or time-delayed phishing links that pass initial scanning, directly satisfying the stem's requirement for advanced protection against sophisticated email threats.
- ✓
FortiSandbox integration for email attachments
Why this is correct
FortiSandbox integration detonates suspicious attachments in an isolated environment, detecting zero-day malware and evasive threats that signature-based antivirus misses. This satisfies the requirement for advanced threat protection against sophisticated email-borne attacks, complementing antispam and antivirus features.
- ✗
Anti-Spam filter
Why it's wrong here
Anti-spam filtering addresses bulk unsolicited mail, not sophisticated threats such as spear-phishing, malicious attachments or impersonation, so it does not satisfy the advanced-protection requirement. It is tempting because spam filtering is a standard FortiMail baseline feature, and would be correct for reducing nuisance mail volume.
- ✓
DMARC verification
Why this is correct
DMARC verification enforces the domain owner's published policy on SPF and DKIM alignment, so spoofed sender addresses are quarantined or rejected. This satisfies the requirement for advanced protection against sophisticated email threats such as exact-domain impersonation.
- ✗
Attachment size limits
Why it's wrong here
Attachment size limits only cap message volume; they inspect no content and block no malicious payload, so they add nothing against sophisticated threats. They are tempting as basic hygiene against oversized mail or storage exhaustion, but the question demands inspection features such as antivirus, sandboxing and content disarm, not a transport constraint.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.