Courseiva
Advanced Threat Protection →mediumMultiple Choice

NSE7 Advanced Threat Protection Practice Question

An administrator is configuring a FortiGate to block outbound traffic to known malicious IP addresses. They want the block list to be updated automatically from a commercial threat intelligence service that provides a REST API. Which FortiGate feature should be used?

⚠ Common exam trap

The trap here is assuming that FortiGuard IP Reputation can be pointed at any external feed, when it is a fixed Fortinet service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

External Threat Feed connector

The External Threat Feed connector is designed to ingest IP or domain blocklists from external HTTP/HTTPS sources, including REST APIs. It automates updates and integrates with firewall policies. The other options are either manual, domain-focused, or tied to Fortinet's own reputation service, which cannot be customized to an arbitrary third-party feed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    FortiGuard IP Reputation service

    Why it's wrong here

    FortiGuard IP Reputation is a subscription service maintained by Fortinet, not by a third-party commercial provider. It cannot be customized to pull from an arbitrary REST API. The scenario requires integration with a specific external service, so the built-in FortiGuard service does not meet the requirement.

  • ✓

    External Threat Feed connector

    Why this is correct

    The External Threat Feed connector allows the FortiGate to poll an external HTTP/HTTPS server or REST API for a list of malicious IPs or domains. The administrator can configure the connector with the feed URL, refresh interval, and authentication. The fetched entries are stored as a threat feed object that can be referenced in firewall policies or blocklists, enabling automatic updates.

  • ✗

    DNS Filter with botnet C&C category

    Why it's wrong here

    DNS Filter blocks domain names, not IP addresses. The scenario is about blocking outbound traffic to malicious IPs. While DNS filtering can prevent resolution, it does not directly block IP-based connections if the IP is already known or if the domain is not used. This option does not satisfy the need for an IP blocklist from an external feed.

  • ✗

    Static firewall address objects

    Why it's wrong here

    Static address objects require manual creation and updates. They do not automatically refresh from an external source. The scenario explicitly requires automatic updates from a commercial threat intelligence REST API. Manual objects would quickly become stale and do not provide the desired automation.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.