NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator configures an automation stitch in FortiManager to execute a CLI script on a FortiGate when a specific event is triggered. The automation stitch is enabled but does not run when the event occurs. What is the most likely cause?
⚠ Common exam trap
It's easy for candidates to assume enabling the automation stitch in FortiManager is sufficient for it to run on the FortiGate, overlooking the critical step of installing the configuration to the managed device, which is a common point of failure in centralized management workflows.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The automation stitch has not been installed to the FortiGate
In FortiManager, automation stitches are created and stored in the central management database but must be explicitly installed to the managed FortiGate via the 'Install Wizard' or a direct policy/object install. Until the stitch is installed, the FortiGate does not have the configuration locally, so even if the stitch is enabled in FortiManager and the event occurs, the FortiGate will not execute the CLI script. This is a common oversight where administrators assume enabling the stitch in FortiManager automatically pushes it to the device.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The event trigger is set to high severity only
Why it's wrong here
Severity filtering governs which events reach the stitch, but a high-severity-only trigger still fires on qualifying events; it would not suppress all executions. This setting is genuinely useful when limiting automation to critical alerts, so it is tempting here, yet it cannot explain a stitch that never runs at all.
- ✗
The FortiGate does not support automation stitches
Why it's wrong here
Automation stitches are a FortiManager feature pushed to managed FortiGates; support is determined by FortiOS version, and most current devices support them. It is tempting to blame the device, but the usual cause is the stitch not being installed or the trigger not matching.
- ✓
The automation stitch has not been installed to the FortiGate
Why this is correct
Automation stitches must be installed to the managed FortiGate before they can execute; enabling the stitch in FortiManager alone leaves it uninstalled on the device. Installation pushes the configuration and triggers to the FortiGate, so the event cannot fire until this occurs.
- ✗
The CLI script contains an invalid command
Why it's wrong here
An invalid CLI command would cause the script to fail after the stitch triggers, not prevent the stitch from running. Script validation is a real concern when authoring CLI scripts, making this tempting, but the stem states the stitch does not execute, so the trigger or configuration is at fault.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.