NSE7 Advanced Threat Protection Practice Question
A security team is using FortiSandbox to analyze suspicious files. They notice that some files are being analyzed but the verdicts are not being sent back to the FortiGate, so the firewall is not blocking them. Which FortiSandbox setting should the administrator verify to ensure verdicts are returned to the FortiGate?
⚠ Common exam trap
The trap here is assuming that licensing or analysis mode affects verdict delivery, when the primary cause is often a misconfigured API key or IP address on the FortiGate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The FortiGate is not configured with the correct FortiSandbox IP address and API key.
The most common reason for missing verdicts is incorrect integration settings on the FortiGate. The FortiGate must have the FortiSandbox's IP address and API key configured correctly to receive verdicts. Without this, files may be submitted, but the firewall cannot authenticate or retrieve results, so blocking does not occur. Verifying these settings resolves the issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The FortiSandbox is configured to use 'Analysis' mode instead of 'Inline' mode.
Why it's wrong here
'Analysis' mode is the standard mode where files are submitted and analyzed asynchronously. It does not prevent verdicts from being returned; verdicts are still sent back to the FortiGate. The issue is likely related to connectivity or configuration of the verdict return path, not the analysis mode. Inline mode is used for real-time blocking but is not required for verdicts.
- ✗
The FortiGate is using a different protocol for file submission than for verdict retrieval.
Why it's wrong here
FortiGate and FortiSandbox communicate using a proprietary protocol over a specific port (typically TCP 514 or 443). The same connection is used for submission and verdict retrieval. Using different protocols is not a supported scenario and would not be the cause; the integration settings must match on both sides.
- ✗
The FortiSandbox is not licensed for verdict submission.
Why it's wrong here
FortiSandbox licensing typically covers the number of submissions and analysis capabilities, but verdict submission back to FortiGate is a core feature and is not separately licensed. The problem is more likely a misconfiguration of the integration settings, such as the API key or network connectivity, rather than a licensing issue.
- ✓
The FortiGate is not configured with the correct FortiSandbox IP address and API key.
Why this is correct
For FortiSandbox to return verdicts to FortiGate, the FortiGate must be configured with the FortiSandbox's IP address and a valid API key. If these are incorrect or missing, the FortiGate cannot authenticate or receive verdicts. The administrator should verify this configuration to ensure verdicts are delivered and acted upon.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.