NSE7 Advanced Threat Protection Practice Question
An administrator is configuring a FortiGate to detect and block command and control (C2) traffic using FortiGuard's Indicator of Compromise (IoC) service. The administrator wants to ensure that the firewall checks DNS queries and HTTP requests against the IoC database. Which feature should be enabled on the FortiGate to accomplish this?
⚠ Common exam trap
The trap here is assuming that any C2 blocking feature uses the IoC service, when in fact the IoC service is a distinct connector that must be explicitly enabled.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FortiGuard IoC Service in the security fabric connector
The FortiGuard IoC Service is a security fabric connector that enables FortiGate to download indicators of compromise and inspect traffic, including DNS and HTTP, against that database. It provides comprehensive detection of C2 communications and other malicious activities. Other features like web filtering or DNS filtering may block some C2 traffic but do not utilize the IoC service as required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
FortiGuard IoC Service in the security fabric connector
Why this is correct
The FortiGuard IoC Service, configured as a security fabric connector, allows FortiGate to download and use indicators of compromise to detect and block malicious traffic. It inspects DNS and HTTP traffic against the IoC database, providing broad protection against known threats. This is the correct feature to enable for the described requirement.
- ✗
Botnet C&C IP Blocklist in the firewall policy
Why it's wrong here
The Botnet C&C IP Blocklist blocks traffic to known botnet command and control IP addresses. It is a valuable feature but does not inspect DNS queries or HTTP requests against the IoC database. The IoC service includes domains, URLs, and IPs, and requires a different feature to be fully utilized. This option is too narrow.
- ✗
DNS Filter profile with botnet C&C domain blocking
Why it's wrong here
DNS Filter can block DNS queries to known botnet C&C domains, but it does not use the IoC service. It relies on FortiGuard's DNS category database. While it can block C2 domains, it does not inspect HTTP requests or leverage the IoC feed. Therefore, it does not fully meet the scenario's requirement.
- ✗
FortiGuard Category Based Filter in the web filter profile
Why it's wrong here
FortiGuard Category Based Filter blocks or allows web traffic based on URL categories, such as 'Malware' or 'Command and Control'. While it can block known C2 domains, it does not directly use the IoC service. The IoC service is a separate feed of compromised indicators, so this option is not the correct feature for leveraging IoC data.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.