NSE7 Enterprise Firewall and VDOMs Practice Question
An administrator configures FortiAnalyzer to receive logs from multiple FortiGates. They want to create a report that shows only incidents involving 'critical' severity and specific attack types. Which FortiAnalyzer feature allows the administrator to define such a custom report?
⚠ Common exam trap
NSE7 often tests the distinction between reporting and monitoring features, so candidates might choose FortiView dashboards because they show similar data, but they are not for custom report creation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report datasets and charts
FortiAnalyzer's reporting engine uses datasets and charts to define custom reports. Datasets are SQL-like queries that extract specific log data, and charts visualize that data. By creating a dataset that filters for 'critical' severity and specific attack types, and then adding it to a report, the administrator can generate the desired custom report. Other features like incident management, playbooks, and FortiView dashboards are for real-time monitoring and automated response, not custom report generation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Incident management
Why it's wrong here
Incident management tracks and triages raised incidents; it does not define report content filtered by severity and attack type. It is tempting because incidents are severity-classified, and it would be correct when the requirement is to manage, assign and follow up detected incidents rather than generate a scheduled custom report.
- ✗
Playbooks
Why it's wrong here
Playbooks automate response actions against detected events; they do not construct reports filtered by critical severity and attack type. It is tempting because playbooks consume the same severity and attack-type metadata, and would be correct where the requirement is automated remediation or notification triggered by matching events.
- ✗
FortiView dashboards
Why it's wrong here
FortiView dashboards provide interactive on-screen log visualisation, not a defined, exportable custom report filtered by severity and attack type. It is tempting because dashboards display the same log fields, and would be correct for real-time ad hoc monitoring rather than producing a structured report.
- ✓
Report datasets and charts
Why this is correct
Report datasets and charts let you write SQL queries against the log database, filtering on severity level and attack type before the chart renders. This satisfies the stem's constraint of restricting output to critical-severity incidents of specific attack types, which predefined report templates cannot isolate.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.