Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

An administrator configures FortiAnalyzer to receive logs from multiple FortiGates. They want to create a report that shows only incidents involving 'critical' severity and specific attack types. Which FortiAnalyzer feature allows the administrator to define such a custom report?

⚠ Common exam trap

NSE7 often tests the distinction between reporting and monitoring features, so candidates might choose FortiView dashboards because they show similar data, but they are not for custom report creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Report datasets and charts

FortiAnalyzer's reporting engine uses datasets and charts to define custom reports. Datasets are SQL-like queries that extract specific log data, and charts visualize that data. By creating a dataset that filters for 'critical' severity and specific attack types, and then adding it to a report, the administrator can generate the desired custom report. Other features like incident management, playbooks, and FortiView dashboards are for real-time monitoring and automated response, not custom report generation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Incident management

    Why it's wrong here

    Incident management tracks and triages raised incidents; it does not define report content filtered by severity and attack type. It is tempting because incidents are severity-classified, and it would be correct when the requirement is to manage, assign and follow up detected incidents rather than generate a scheduled custom report.

  • ✗

    Playbooks

    Why it's wrong here

    Playbooks automate response actions against detected events; they do not construct reports filtered by critical severity and attack type. It is tempting because playbooks consume the same severity and attack-type metadata, and would be correct where the requirement is automated remediation or notification triggered by matching events.

  • ✗

    FortiView dashboards

    Why it's wrong here

    FortiView dashboards provide interactive on-screen log visualisation, not a defined, exportable custom report filtered by severity and attack type. It is tempting because dashboards display the same log fields, and would be correct for real-time ad hoc monitoring rather than producing a structured report.

  • ✓

    Report datasets and charts

    Why this is correct

    Report datasets and charts let you write SQL queries against the log database, filtering on severity level and attack type before the chart renders. This satisfies the stem's constraint of restricting output to critical-severity incidents of specific attack types, which predefined report templates cannot isolate.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.