Courseiva
Advanced Threat Protection →mediumMultiple Choice

NSE7 Advanced Threat Protection Practice Question

An administrator configures an automation stitch to respond to a high severity event. The trigger is 'event' and the action is 'CLI script'. What must be defined for the action to execute properly?

⚠ Common exam trap

Candidates often assume a CLI script action requires an external orchestrator like FortiManager or authentication tokens, when in fact the script runs locally on the FortiGate and only needs a valid script definition.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A valid CLI script that contains commands to be executed on the FortiGate

For an automation stitch action of type 'CLI script' to execute properly on a FortiGate, the action must reference a valid CLI script that contains the actual FortiGate CLI commands to be run. The script is defined locally on the FortiGate and does not require external authentication, a FortiManager, or an email server for execution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An API token for authentication

    Why it's wrong here

    CLI script actions execute locally under the administrator's existing session privileges, requiring no API token; tokens authenticate external REST API calls. It is tempting because automation stitches invoking external systems do need credentials, and an API token would be correct for an action calling the FortiGate API remotely.

  • ✗

    A FortiManager to execute the script

    Why it's wrong here

    A CLI script action runs locally on the FortiGate itself, so no FortiManager is required; FortiManager executes scripts only for its own script actions. It is tempting because FortiManager centrally manages configuration scripts, which would be the right component for scheduled or multi-device script deployment.

  • ✗

    An email server to send the script output

    Why it's wrong here

    An email server is only needed for the email action, not for executing a CLI script; the script runs regardless of notification configuration. It is tempting because alerting on high-severity events is a common stitch goal, and email would be correct if the action were notification rather than command execution.

  • ✓

    A valid CLI script that contains commands to be executed on the FortiGate

    Why this is correct

    The CLI script action executes FortiGate commands, so a valid script containing those commands must exist and be referenced for the stitch to run. Without it the action has nothing to execute, so defining the script satisfies the stem's requirement for proper action execution.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.