NSE7 Advanced Threat Protection Practice Question
A security team uses FortiSandbox in a FortiGate security fabric. They want files that receive a 'Malicious' verdict to be automatically quarantined and their source endpoints isolated without manual intervention. Which combination of Fortinet components and features must be configured to achieve this automated response?
⚠ Common exam trap
The trap here is assuming that any Fortinet security fabric component can automatically isolate an endpoint, when only FortiClient EMS provides that endpoint containment action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FortiSandbox 'Automation stitches' with FortiGate and FortiClient EMS to trigger quarantine and endpoint isolation.
Automated response to a FortiSandbox malicious verdict requires an automation stitch that links the sandbox to enforcement points. FortiSandbox can trigger actions on FortiGate to block the file and quarantine the host, and on FortiClient EMS to isolate the endpoint. Other components such as FortiAnalyzer, FortiMail, or FortiGuard feeds do not provide the direct endpoint isolation needed here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
FortiGate 'Security Fabric' connectors with FortiAnalyzer playbooks to push blocklists to FortiMail.
Why it's wrong here
FortiAnalyzer playbooks can automate some response actions, but they are not the mechanism that ties a FortiSandbox malicious verdict to endpoint isolation. FortiMail is an email security appliance and does not quarantine endpoint files or isolate hosts. This combination misroutes the response and cannot achieve the required endpoint containment.
- ✓
FortiSandbox 'Automation stitches' with FortiGate and FortiClient EMS to trigger quarantine and endpoint isolation.
Why this is correct
FortiSandbox automation stitches can call FortiGate and FortiClient EMS actions when a malicious verdict is generated. FortiGate can block the file hash and quarantine the infected host, while FortiClient EMS can isolate the endpoint. This is the intended fabric-level automated response path for sandbox verdicts, so it correctly delivers quarantine and isolation without manual steps.
- ✗
FortiGate 'Threat Feed' with FortiGuard IOC service and manual firewall policy updates.
Why it's wrong here
FortiGuard IOC feeds provide indicators that FortiGate can use for blocking, but they do not automatically quarantine files or isolate endpoints based on a FortiSandbox verdict. Manual firewall policy updates introduce delay and do not perform endpoint containment. This option does not provide the automated quarantine and isolation the scenario requires.
- ✗
FortiSandbox 'Scan Profile' with 'Block Malicious Files' enabled and FortiGate AV quarantine.
Why it's wrong here
A scan profile with block malicious files only controls how the sandbox treats detections within its own analysis. FortiGate AV quarantine acts on files inspected by FortiGate, not on sandbox verdicts, and neither component can isolate an endpoint. This option omits the endpoint management integration required for automated isolation.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.