Courseiva
Advanced Threat Protection →mediumMultiple Choice

NSE7 Advanced Threat Protection Practice Question

An administrator is configuring a FortiGate to detect and block traffic to known malicious domains using DNS filtering. The administrator wants to ensure that DNS queries for malicious domains are blocked and that users are redirected to a block page. Which DNS filter action should be configured?

⚠ Common exam trap

Candidates often confuse the 'Block' action with 'Redirect'; only 'Redirect' provides a block page, while 'Block' silently drops the query.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Redirect

The 'Redirect' action in DNS filtering blocks resolution of malicious domains and redirects the user to a FortiGate block page, satisfying both blocking and user notification. 'Block' only drops the query, 'Allow' permits access, and 'Monitor' only logs. Therefore, 'Redirect' is the correct choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Block

    Why it's wrong here

    The 'Block' action in DNS filtering simply drops the DNS query, preventing resolution. However, it does not redirect the user to a block page; the user will see a generic DNS error. The scenario requires redirection to a block page, so 'Block' alone is insufficient. It is a valid action but does not meet the requirement for user notification.

  • ✓

    Redirect

    Why this is correct

    The 'Redirect' action in DNS filtering sends the user to a FortiGate block page when they attempt to access a malicious domain. This not only blocks the DNS resolution but also informs the user why access is denied. It satisfies both requirements: blocking malicious domains and showing a block page. This is the appropriate action for the described scenario.

  • ✗

    Monitor

    Why it's wrong here

    The 'Monitor' action logs the DNS query but allows it to proceed. It does not block the domain or redirect the user. While useful for auditing, it does not provide any enforcement. Since the requirement is to block and redirect, 'Monitor' is not suitable.

  • ✗

    Allow

    Why it's wrong here

    The 'Allow' action permits the DNS query to proceed, which means the malicious domain would resolve and the user could access it. This is the opposite of what the administrator wants. 'Allow' is used for exceptions or trusted domains, not for blocking. Therefore, it is incorrect for this scenario.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.