Courseiva
Advanced Threat ProtectionmediumMultiple ChoiceObjective-mapped

NSE7 Advanced Threat Protection Practice Question

An administrator is deploying FortiClient with ATP features. They want to ensure that if a process is detected as malicious by the FortiClient machine learning engine, the endpoint is isolated from the network. Which configuration should they use?

⚠ Common exam trap

Test-takers frequently confuse endpoint file quarantine (antivirus profile) with network quarantine (automation stitch), leading candidates to select Option D, which only addresses local file remediation, not network isolation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure an automation stitch with trigger 'FortiClient event' and action 'quarantine endpoint'

An automation stitch with the trigger 'FortiClient event' and action 'quarantine endpoint' allows FortiGate to automatically isolate an endpoint when the FortiClient machine learning engine detects a malicious process. This integration leverages FortiGate's Security Fabric to enforce network isolation based on endpoint telemetry, ensuring the compromised host is blocked from communicating with the rest of the network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a firewall policy to block traffic from that endpoint

    Why it's wrong here

    Manual policy does not automate response to detection.

  • Enable 'auto-network-access' in the FortiClient profile

    Why it's wrong here

    Auto-network-access controls VPN connectivity, not endpoint isolation.

  • Configure an automation stitch with trigger 'FortiClient event' and action 'quarantine endpoint'

    Why this is correct

    Automation stitches can respond to FortiClient events and isolate the endpoint.

  • Enable 'FortiClient quarantine' in the antivirus profile

    Why it's wrong here

    Antivirus profile does not control FortiClient endpoint isolation.

About these practice questions

Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.