Courseiva
Advanced Threat ProtectionhardMultiple ChoiceObjective-mapped

NSE7 Advanced Threat Protection Practice Question

An administrator configures a WAF profile on FortiGate to protect a web application. They notice that SQL injection attacks are not being blocked. What is the MOST likely reason?

⚠ Common exam trap

A common mix-up: candidates assume a WAF profile in monitor mode is the most likely cause of attacks not being blocked, but the question emphasizes 'most likely' and the inactive subscription is a more fundamental prerequisite for signature-based detection to function at all.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The FortiGuard Web Filtering subscription is inactive

The FortiGuard Web Filtering subscription provides the signature database required to detect and block SQL injection attacks within a WAF profile. Without an active subscription, the WAF profile cannot update or use the latest attack signatures, rendering it unable to identify SQL injection patterns even if the profile is enabled and applied correctly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The web application uses HTTPS without SSL inspection

    Why it's wrong here

    FortiGate WAF can inspect HTTPS if SSL inspection is enabled, but the question doesn't mention encryption.

  • The FortiGuard Web Filtering subscription is inactive

    Why this is correct

    WAF signatures are part of FortiGuard Web Filtering; without subscription, updates stop.

  • The WAF profile is set to monitor mode

    Why it's wrong here

    If in monitor mode, it would log but not block, not fail to detect.

  • The WAF profile is applied to the wrong firewall policy

    Why it's wrong here

    If applied correctly, it would block known attacks.

About these practice questions

This NSE7 question is part of Courseiva's 940-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.