NSE7 Advanced Threat Protection Practice Question
An administrator is configuring a FortiGate to detect and block traffic to known malicious domains using DNS filtering. The administrator wants to ensure that DNS queries for malicious domains are blocked and that users are redirected to a block page. Which DNS filter action should be configured?
⚠ Common exam trap
Candidates often confuse the 'Block' action with 'Redirect'; only 'Redirect' provides a block page, while 'Block' silently drops the query.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Redirect
The 'Redirect' action in DNS filtering blocks resolution of malicious domains and redirects the user to a FortiGate block page, satisfying both blocking and user notification. 'Block' only drops the query, 'Allow' permits access, and 'Monitor' only logs. Therefore, 'Redirect' is the correct choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block
Why it's wrong here
The 'Block' action in DNS filtering simply drops the DNS query, preventing resolution. However, it does not redirect the user to a block page; the user will see a generic DNS error. The scenario requires redirection to a block page, so 'Block' alone is insufficient. It is a valid action but does not meet the requirement for user notification.
- ✓
Redirect
Why this is correct
The 'Redirect' action in DNS filtering sends the user to a FortiGate block page when they attempt to access a malicious domain. This not only blocks the DNS resolution but also informs the user why access is denied. It satisfies both requirements: blocking malicious domains and showing a block page. This is the appropriate action for the described scenario.
- ✗
Monitor
Why it's wrong here
The 'Monitor' action logs the DNS query but allows it to proceed. It does not block the domain or redirect the user. While useful for auditing, it does not provide any enforcement. Since the requirement is to block and redirect, 'Monitor' is not suitable.
- ✗
Allow
Why it's wrong here
The 'Allow' action permits the DNS query to proceed, which means the malicious domain would resolve and the user could access it. This is the opposite of what the administrator wants. 'Allow' is used for exceptions or trusted domains, not for blocking. Therefore, it is incorrect for this scenario.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.