NSE7 Advanced Threat Protection Practice Question
An administrator is configuring a FortiGate to use the external threat feed feature to block traffic from known malicious IP addresses. They want to ensure that the feed is automatically updated and that the firewall blocks traffic based on the feed. Which two actions must the administrator perform? (Choose two.)
⚠ Common exam trap
The trap here is thinking that enabling antivirus or DNS filtering will enforce a threat feed; threat feed blocking requires a dedicated object and a deny policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the external threat feed object as a source or destination in a firewall policy with a deny action.
To use an external threat feed for blocking, the administrator must first create the threat feed object with the feed URL, then reference that object in a firewall policy with a deny action. The FortiGate will download and update the feed automatically, and the policy will block matching traffic. Other options do not achieve IP-based blocking from a threat feed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add the external threat feed object as a source or destination in a firewall policy with a deny action.
Why this is correct
After creating the threat feed object, it must be used in a firewall policy. By adding it as a source or destination and setting the action to deny, FortiGate will block traffic matching the feed entries. This enforces the threat intelligence and prevents communication with malicious IPs.
- ✗
Enable FortiGuard antivirus scanning on the firewall policy.
Why it's wrong here
FortiGuard antivirus scanning inspects files for malware but does not block IP addresses from an external threat feed. While antivirus is important, it is not required for threat feed enforcement. The scenario focuses on IP-based blocking, so this action is irrelevant to the requirement.
- ✓
Create an external threat feed object and specify the URL of the threat feed.
Why this is correct
Creating an external threat feed object is the first step. The administrator must provide the URL where the feed is hosted, and configure the update interval. FortiGate will periodically download the list of IP addresses or domains. This object is then referenced in firewall policies to enforce blocking.
- ✗
Set the threat feed object to 'monitor' mode in the firewall policy.
Why it's wrong here
Setting the threat feed object to 'monitor' mode would only log traffic matching the feed, not block it. The requirement is to block traffic, so the firewall policy action must be 'deny'. Monitor mode is useful for testing but does not enforce blocking.
- ✗
Configure a DNS filter profile to block the malicious IP addresses.
Why it's wrong here
DNS filter profiles are used to block or allow DNS queries based on categories or domain names, not IP addresses. They cannot directly block traffic to specific IPs from a threat feed. The external threat feed feature is designed for IP or domain blocking at the firewall policy level, not DNS filtering.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.