NSE7 Advanced Threat Protection Practice Question
A security team is deploying FortiEDR to protect endpoints. They want to ensure that when a threat is detected, the endpoint is automatically isolated from the network to prevent lateral movement. However, they also need to allow the endpoint to communicate with the FortiEDR management server for updates and remediation. Which FortiEDR feature should they configure to achieve this?
⚠ Common exam trap
It's easy for candidates to confuse network isolation with simply blocking malicious traffic, and assuming that external firewall policies are needed instead of FortiEDR's built-in playbook actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Playbook with network isolation action
FortiEDR playbooks enable automated response actions, including network isolation. The isolation action blocks all network traffic except to the FortiEDR management server, allowing the endpoint to remain managed and receive remediation instructions. This satisfies the requirement of automatic isolation while preserving management connectivity. Other options like application control, device control, or FortiGate policies do not provide the same integrated, automated endpoint isolation capability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall policy on FortiGate
Why it's wrong here
A FortiGate firewall policy can block traffic from an endpoint if integrated with FortiEDR, but it does not automatically isolate the endpoint upon threat detection unless a specific integration is configured. FortiEDR's native isolation feature is more direct and does not require external firewall changes. The scenario asks for a FortiEDR feature, so this is not the correct answer.
- ✗
Device control policy
Why it's wrong here
Device control policies restrict the use of peripheral devices like USB drives. They do not affect network connectivity or provide isolation. This feature is useful for data loss prevention but does not address the need to isolate an endpoint from the network while maintaining management communication.
- ✗
Application control policy
Why it's wrong here
Application control policies manage which applications can run on endpoints. They do not provide network isolation or containment. While they can block malicious processes, they do not prevent lateral movement by isolating the endpoint from the network. This feature is unrelated to the requirement of automatic network isolation upon threat detection.
- ✓
Playbook with network isolation action
Why this is correct
FortiEDR playbooks allow automated responses to threats. A playbook can include a network isolation action that blocks all network traffic except communication with the FortiEDR management server. This ensures the endpoint is contained while still allowing updates and remediation. This feature meets both requirements: automatic isolation and continued management connectivity. It is the correct choice for automated containment.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.