NSE7 Advanced Threat Protection Practice Question
An administrator wants to configure FortiGate to automatically block a source IP when a high-severity IPS event is detected. Which TWO components must be configured? (Choose two.)
⚠ Common exam trap
A common mix-up: candidates assume enabling IPS on a firewall policy (Option A) is sufficient for automatic blocking, but FortiGate requires an explicit automation stitch to convert detection into an automated quarantine action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An automation stitch trigger set to 'IPS Event'
Option C is correct because an automation stitch must have a trigger that fires on the relevant log event, and setting the trigger to 'IPS Event' (specifically matching high-severity IPS logs) is what initiates the automated response when the IPS sensor detects the threat. Option E is correct because the stitch also needs an action that performs the blocking; the 'Quarantine' action adds the offending source IP to the quarantine list so FortiGate drops subsequent traffic from it. Together, the IPS Event trigger and the Quarantine action form the automation stitch that automatically blocks the source IP. Option A is not required by the question because, while IPS must be enabled somewhere for events to occur, the question asks specifically about the automation components needed to block the source, not the base policy configuration. Option B is incorrect because FortiGuard category subscription relates to web filtering/security rating services, not to triggering IPS-based quarantine. Option D is incorrect because a static route to the source IP is unrelated to dynamically blocking a detected attacker.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A firewall policy with IPS enabled
Why it's wrong here
An IPS-enabled firewall policy is where inspection occurs, but it only detects and logs the high-severity event; it does not itself add the source to a blocklist. The automatic blocking requires a separate automation stitch or action. A policy with IPS is the right answer when the goal is merely detection and logging.
- ✗
A FortiGuard category subscription
Why it's wrong here
A FortiGuard category subscription provides web-filtering and IPS signature updates; it plays no role in dynamically banning a source address. Automatic blocking depends on an automation stitch triggered by the IPS log, not on subscription licensing. The subscription would be the correct component if the requirement were keeping signature databases current.
- ✓
An automation stitch trigger set to 'IPS Event'
Why this is correct
The IPS Event trigger is what detects the high-severity signature hit and fires the stitch; without it, no automation runs. It supplies the event context, including the offending source IP, that the paired action needs to block traffic automatically.
- ✗
A static route to the source IP
Why it's wrong here
A static route merely dictates the path packets take toward the source IP; it cannot deny traffic. Automatic blocking needs an automation stitch that adds the address to a quarantine or blocklist. A static route would be the right configuration when the requirement is reachability to a specific network, not enforcement.
- ✓
An automation stitch action set to 'Quarantine'
Why this is correct
The Quarantine action is the enforcement half: it instructs FortiGate to add the offending source IP to the quarantine list, blocking it. Paired with the IPS Event trigger, it satisfies the requirement to block automatically rather than merely log.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.