Courseiva
Advanced Threat Protection →mediumMultiple Choice

NSE7 Advanced Threat Protection Practice Question

An administrator wants to automatically block a file that FortiSandbox has determined to be malicious. The FortiGate is configured with an antivirus profile that includes FortiSandbox submission. Which verdict action should be set to 'block' in the antivirus profile to achieve this?

⚠ Common exam trap

Watch out — candidates often confuse 'Unknown' with 'Malicious' and think blocking unknown files is safer, but FortiSandbox's 'Unknown' verdict means the file could not be analyzed (e.g., due to size or timeout), and blocking it would disrupt legitimate traffic; the correct approach is to block only confirmed malicious files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Malicious

The 'Malicious' verdict action in the antivirus profile is specifically designed to block files that FortiSandbox has determined to be malicious. When FortiSandbox submits a file and returns a 'malicious' verdict, the FortiGate uses this action to enforce blocking, ensuring the file is not delivered to the end user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Exempted

    Why it's wrong here

    Exempted applies to files on the administrator's exemption list, which bypass scanning and are never submitted to FortiSandbox. Blocking them would contradict the exemption's purpose. It would be the correct setting only when the requirement is to override a verdict for trusted files.

  • ✗

    Unknown

    Why it's wrong here

    Unknown covers files FortiSandbox has not yet returned a verdict on, such as submissions still queuing. Blocking it would drop unscanned files rather than confirmed malicious ones. It would be correct where policy demands quarantine until a verdict arrives, not for blocking confirmed malware.

  • ✓

    Malicious

    Why this is correct

    Setting the Malicious verdict to block lets the FortiGate drop files that FortiSandbox has already confirmed as malicious, satisfying the requirement for automatic blocking. Other verdicts, such as High Risk, cover suspicious but unconfirmed files, so they would not reliably block only sandbox-confirmed malware.

  • ✗

    Clean

    Why it's wrong here

    The Clean verdict action governs files FortiSandbox reports as benign, so setting it to block would drop legitimate traffic while malicious verdicts pass. It is tempting because Clean appears in the same verdict list, but the Malicious verdict action is the one that must be set to block.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.