NSE7 Advanced Threat Protection Practice Question
An administrator is configuring a FortiGate to use the FortiGuard Web Filter to block access to newly registered domains that are often used in phishing campaigns. The administrator wants the block to occur with minimal impact on legitimate business traffic and without relying on manual URL submissions. Which FortiGuard Web Filter category should be used?
⚠ Common exam trap
Watch out — candidates often confuse the reactive Malicious Websites category with the proactive Newly Observed Domain category, which is specifically intended for recently registered domains.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Newly Observed Domain
Newly Observed Domain is a FortiGuard category that identifies domains registered recently, which are disproportionately used in phishing and malware campaigns. Blocking it provides proactive protection against unknown malicious domains without manual URL submission. Other categories either target different threat types or are reactive, so they do not meet the requirement for minimal-impact, automated blocking of newly registered domains.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Potentially Unwanted Program
Why it's wrong here
Potentially Unwanted Program addresses software that may be unwanted but is not necessarily malicious, such as adware or toolbars. It does not identify newly registered domains used for phishing, so enabling it would not block the targeted threat and would instead affect unrelated software downloads, failing the scenario's objective.
- ✓
Newly Observed Domain
Why this is correct
The Newly Observed Domain category is designed to flag domains that have recently appeared and are frequently associated with malicious activity such as phishing. Blocking this category provides proactive protection without manual submissions and typically has low false-positive impact on established business domains, making it the appropriate choice for this requirement.
- ✗
Malicious Websites
Why it's wrong here
Malicious Websites blocks domains already confirmed as malicious by FortiGuard. While valuable, it is reactive and will not block a newly registered domain until it has been classified as malicious, leaving a window of exposure. The scenario specifically calls for blocking newly registered domains, so this category alone does not satisfy the requirement.
- ✗
Dynamic DNS
Why it's wrong here
The Dynamic DNS category covers domains hosted by dynamic DNS providers, which are sometimes abused but also legitimately used for remote access and small business services. Blocking it would not specifically target newly registered phishing domains and could disrupt legitimate dynamic DNS traffic, so it fails to meet the minimal-impact requirement.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.